Cyber News: Week Ending December 19, 2025

The holiday season is in full swing and threat actors are busy too, deploying their tried-and-true methods as well as exploiting the latest vulnerabilities. Here are this week’s most important cybersecurity stories with quick steps you can take to protect yourself and your business.

1. AI‑powered scams getting harder to spot
Cybercriminals are using artificial intelligence to write convincing emails, messages, and even fake phone calls that look and sound like they’re from real companies or your own coworkers. These scams often trick people into sending payments, sharing passwords, or installing harmful software on work and personal devices.

BET-R Actions: Treat unexpected money or password requests as suspicious, even if they “look right”. Confirm anything sensitive by a second method (call the person on a known number, not the one in the message). Use multifactor authentication (MFA) on email, banking, accounting, and social media accounts so a stolen password alone is not enough. Train staff regularly with short phishing-awareness exercises and share examples of recent scam emails your team receives.[1][2][3]

2. Ransomware still hitting small businesses
Ransomware groups continue to lock up company data and demand payment, with many attackers specifically targeting small and mid-sized businesses they think have weaker defenses. A large share of these attacks start because of stolen passwords, unpatched systems, or known gaps that were never fixed.

BET-R Actions: Keep at least one backup that is offline or in a secure cloud account that staff cannot easily overwrite; test restoring it regularly. Turn on automatic updates for operating systems, routers, and key business apps so known holes get patched quickly. Require strong, unique passwords plus MFA for remote access, email, and admin accounts. Limit who has administrator rights on computers and business systems to reduce damage if one account is hacked.[4][5]

3. Data breaches fueling highly targeted phishing
Recent breaches at large companies have exposed names, email addresses, phone numbers, and other contact details that criminals now use to craft highly believable scam messages. Even when passwords or card numbers are not leaked, this “basic” info is enough to create phishing emails and texts that sound personal and urgent.

BET-R Actions: Assume your email and phone number are already in criminals’ databases; be extra cautious with any “account alert” or delivery message. Go directly to a company’s website or app instead of clicking links in emails or texts when asked to log in or fix a problem. Use a password manager so each account has a different password; that way, a breach at one site does not unlock everything. For your business, keep an inventory of which services hold customer data and review their security notices and breach history.[4][6][7][8][9]

4. Fake apps, VPNs, and tools pushing malware
Scammers are promoting fake security apps, VPNs, and “productivity tools” that claim to protect your privacy or speed up your device but instead steal data or give attackers remote control. These often appear in ads, search results, or app stores with good-looking (but fake) reviews boosted by AI.

BET-R Actions: Only install apps from official app stores and from companies you recognize and can verify. For VPNs, password managers, or security tools, stick to well-known brands recommended by trusted industry sites or your IT provider. Be wary of apps that demand broad permissions (access to SMS, contacts, screen recording) without a clear need. On business devices, restrict who can install software and maintain a short approved list of tools.[2][3][4]

5. Online reviews and “too good to be true” offers
AI-generated fake reviews are flooding review sites and online marketplaces, helping scammers sell low-quality or outright fraudulent products and services, including “IT support” and “recovery services” after a hack. Some scammers also threaten businesses with negative reviews unless they pay up.

BET-R Actions: Look beyond star ratings; read a sample of reviews and watch for vague, repetitive, or copy-paste style comments. Be skeptical of offers that combine very low prices with urgent deadlines (“today only”, “limited spots”) for tech or marketing services. If you are targeted with review extortion, document everything, report it to the platform, and avoid paying, which often leads to more demands. For your business, claim and monitor your official profiles on major review platforms so you can quickly spot suspicious activity.[2][3]

This week, individuals and small businesses face the greatest cybersecurity risks from convincing phishing scams and stolen credentials rather than advanced, cinematic-style hacks. Strengthen your defenses by enabling multi-factor authentication (MFA) on all key accounts, verifying links before clicking, using strong and unique passwords, and maintaining reliable, offline backups. These simple steps can stop or greatly reduce the damage from most active threats circulating right now.

Recent Trends and Incidents

Each week, more companies are impacted by data breaches or cyber attacks that potentially impact your personal information. Here are a few high‑level examples of organizations that reported or disclosed cyber incidents in the last week.

  • University of Sydney
    The University of Sydney in Australia announced a cyber breach where older (“historic”) information about some members of its community was accessed by an unauthorized party. At this stage, they have said there is no evidence that current core systems are down, but some personal information from past records may have been viewed.
    What this mean for you:
    Information you gave an organization years ago can still be a target if it is stored in their systems. Ask schools, clubs, or service providers which data they really need to keep and request deletion of old accounts or records when you no longer use a service.[10]
  • DXS International (tech provider for NHS England)
    DXS International, a U.K. company that supplies software used in parts of the National Health Service (NHS) in England, said it was hit by a cyberattack and data breach. A ransomware group claims it stole a large amount of company data, though the company says its main clinical services are still running and it is investigating whether any patient data was taken.
    What this means for you:
    Even if your doctor or hospital is not directly hacked, companies that provide them with software can be weak points. Individuals should watch for unusual health‑related emails or bills; small clinics should review contracts and ask vendors to explain how they protect patient data and what happens if they are breached.[11]
  • Conifer Health Solutions
    Conifer Health Solutions, a U.S. healthcare services company, disclosed a breach that exposed sensitive information about pediatric (children’s) patients in the United States. The data involved varies by person, but can include personal and financial details, and the company has notified regulators and affected families.
    What this means for you:
    Medical and billing companies often hold very detailed information that criminals can use for identity theft or fraud. Parents should freeze or lock their children’s credit files where possible and carefully review any medical bills or insurance statements for charges they do not recognize.[12]
  • Adelman & Gettleman (law firm)
    Adelman & Gettleman, a specialized law firm in the United States, was listed as a victim by the “Akira” ransomware group, which claims to have stolen around 31 GB of the firm’s data. Law firms can hold highly sensitive financial and personal details tied to bankruptcies, business deals, and court cases.
    What this means for you:
    Professional service firms such as lawyers, accountants, and consultants are valuable targets because they hold many clients’ information in one place. When choosing a professional firm, ask simple security questions (for example, “How do you protect client files?” and “Do you use multifactor authentication and backups?”) and be cautious about sending sensitive documents over unencrypted email.[13]
  • Pioneer Ocean Freight Co. (logistics company)
    A logistics and freight‑forwarding company, Pioneer Ocean Freight Co. in Thailand, was reported as a victim of the “NightSpire” ransomware group, which published stolen company data on its dark‑web site. The exposed records reportedly include billing information, employee data, financial records, and other confidential details.
    What this means for you:
    Supply‑chain and transport companies are attractive targets because disrupting them can pressure them to pay quickly. Small businesses that rely on shipping, freight, or other vendors should plan for vendor outages (for example, alternate providers and offline copies of key documents) and avoid sharing more customer data with partners than is strictly necessary.[14]

Recent breaches highlight that attackers often target organizations storing extensive customer and business data, not individuals directly. Once inside, they exploit stolen information for identity fraud, financial scams, and secondary attacks on smaller businesses. Protect your data and operations by using strong, unique passwords, enabling multi‑factor authentication on all critical accounts, and regularly monitoring financial and credit activity. These steps can limit damage and recovery costs even when your trusted vendors or partners experience a breach.


Citations:
[1] 5 Ways Hackers Use AI to Break Into Small Businesses … https://www.cpapracticeadvisor.com/2025/12/03/5-ways-hackers-use-ai-to-break-into-small-businesses-and-how-to-stop-them/174256/
[2] F-Alert US Cyber Threats Bulletin – December 2025 | F‑Secure https://www.f-secure.com/us-en/partners/insights/f-alert-cyber-threats-bulletin-december-2025
[3] The Week in Breach News: November 12, 2025 | Kaseya https://www.kaseya.com/blog/the-week-in-breach-news-11-12-25/
[4] The Latest Small Business Ransomware Statistics (Dec 2025) https://programs.com/resources/small-business-ransomware-stats/
[5] 26 Ransomware Examples Explained in 2025 – SentinelOne https://www.sentinelone.com/cybersecurity-101/cybersecurity/ransomware-examples/
[6] Data Breaches 2025: Biggest Cybersecurity Incidents So Far https://www.pkware.com/blog/recent-data-breaches
[7] Data Breaches That Have Happened This Year (2025 Update) https://tech.co/news/data-breaches-updated-list
[8] DoorDash Confirms Data Breach Exposing Customer Personal … https://www.infosecurity-magazine.com/news/doordash-confirms-data-breach/
[9] 35 Alarming Small Business Cybersecurity Statistics for 2025 https://www.strongdm.com/blog/small-business-cyber-security-statistics
[10] Notification of cyber and data breach https://www.sydney.edu.au/news-opinion/news/2025/12/18/notification-of-cyber-and-data-breach.html
[11] Tech provider for NHS England confirms data breach https://techcrunch.com/2025/12/18/tech-provider-for-nhs-england-confirms-data-breach/
[12] Conifer Data Breach Exposes Sensitive Pediatric Patient Data https://www.claimdepot.com/data-breach/conifer-health-solutions-2025
[13] Adelman & Gettleman Data Breach in 2025 – Breachsense https://www.breachsense.com/breaches/adelman-gettleman-data-breach/
[14] Weekly Intelligence Report – 12 December 2025 https://www.cyfirma.com/news/weekly-intelligence-report-12-december-2025/

Discover more from BET-R Security Solutions

Subscribe now to keep reading and get access to the full archive.

Continue reading

search previous next tag category expand menu location phone mail time cart zoom edit close