Cyber News: Week Ending December 26, 2025

Cyber criminals are still trying to steal the joy of the holiday season, deploying both traditional attacks as well as new techniques thanks to the power of AI. Here are this week’s most important cybersecurity stories with simple (yet effective) actions you can take against the latest cyber threats.

1. Holiday phishing & fake delivery scams
Scammers are blasting out Christmas‑themed phishing emails and texts, including fake delivery notices from brands like Walmart, Home Depot, FedEx, and UPS, with over 33,500 holiday phishing emails spotted in just two weeks and thousands of fake ads per day on social media. Many of these messages use urgent phrases like “final notice” or “delivery failed” to trick people into clicking links that steal card numbers, bank logins, and other personal data, often only noticed after accounts are locked or money is missing.

BET-R Actions: Slow down on anything “urgent” about deliveries, refunds, or offers; instead of clicking, go directly to the retailer’s or shipper’s official app or website. Teach staff and family to never enter passwords or card details on pages opened from a link in email/SMS; type the site address yourself or use bookmarks. Use multi‑factor authentication (text/app code) on bank, email, and shopping accounts so stolen passwords alone are not enough to break in.[1]

2. Wave of attacks on small businesses
Recent reporting shows that nearly half of U.S. small and mid‑sized businesses have been hit by a cyberattack in the past five years, with more than a quarter suffering one in just the last 12 months. Many still rely on an untrained owner or employee to “handle IT,” and most do not have a formal plan for what to do if they are attacked, leaving them exposed to phishing, ransomware, and costly downtime.

BET-R Actions: For business owners, pick one person or vendor to be your “security lead” and give them time and budget to manage backups, updates, and security tools, rather than treating it as a side task. Create a one‑page incident plan: who to call, how to disconnect affected devices, and how to restore from backup; print it and keep an offline copy. Run a 15‑minute phishing awareness session with staff this week; show example scam emails and make a clear rule: “When in doubt, ask before clicking or paying.”[2]

3. Holiday ransomware and malicious attachments
Guidance for December 2025 highlights a spike in ransomware and “double‑extortion” attacks where criminals both lock up a company’s data and threaten to leak it, often delivered through holiday‑themed attachments or links. A single employee opening a malicious attachment can encrypt key systems and halt operations, forcing small businesses into expensive recovery or ransom decisions.

BET-R Actions: Ensure every business device has automatic backups to a system that is not always connected (e.g., a reputable cloud backup); test restoring a file so you know it works. Set a simple rule: no opening of unexpected attachments, especially “invoices,” “holiday cards,” or “bonuses,” without confirming directly with the sender by phone or known contact method. Keep computers, firewalls, and routers updated; schedule a monthly “update day” so patches are not postponed during busy seasons.[3]

4. Data breaches at financial and professional firms
This week includes fresh attention on several consumer‑impacting breaches, such as a regional U.S. bank incident that exposed thousands of individuals’ personal details across multiple states, and an accounting firm breach where customers waited over a year to be notified. Breaches like these often expose names, contact details, and in some cases Social Security numbers and financial information, increasing the risk of identity theft and targeted scams.

BET-R Actions: Turn on alerts for bank and card transactions, and review statements weekly so unusual charges are caught quickly. If notified in any breach, place a free fraud alert or credit freeze with major credit bureaus, and monitor credit reports at least once a year. Small firms that store client data should map what personal data they hold, limit access to “need to know,” and encrypt sensitive files where possible.[4][5][6]

5. Healthcare and local service providers hit
Recent settlements, such as a $750,000 agreement following a breach at VisionPoint Eye Center affecting nearly 67,000 people, show that even local medical and service providers are prime cyber targets. Exposed data can include medical details, insurance information, and identifiers like Social Security numbers, which criminals can use for medical fraud and long‑term identity abuse.

BET-R Actions: As a patient, use the provider’s portal only via direct links or saved bookmarks; be wary of “update your records” emails asking you to log in from a link. Clinics and small offices should enforce unique accounts for each staff member, require strong passwords and multi‑factor authentication on portals and practice‑management software. Keep an inventory of systems that hold patient or customer data and ensure they have regular security updates and tested backups.[6][7]

This week, the most pressing cybersecurity threats for individuals and small businesses come from deceptive phishing attempts and credential theft—not complex, high-tech exploits. Strengthen your protection by enabling multi-factor authentication (MFA) on all critical accounts, verifying sender details and links before taking action, and using strong, unique passwords stored in a reputable password manager. Keep updated, offline backups of essential data to recover quickly if an attack occurs. These proactive measures can effectively block or limit the impact of the current wave of cyber threats circulating right now.

Recent Trends and Incidents

Several well‑known companies disclosed or were linked to cyber incidents in the last week, mostly involving stolen customer data or disrupted operations. Here is a high‑level overview of a few key cases and what they mean for everyday people and small businesses.

  • Aflac – insurance customer data exposed
    Major U.S. insurer Aflac confirmed that data from about 22.7 million customers, beneficiaries, employees, and agents was stolen in a cyberattack and later reported publicly this week. The exposed information reportedly includes personal and health‑related details, which criminals can use for targeted scams, fake insurance calls, or identity theft.
    What this mean for you:
    If you have any Aflac policy, be extra careful with calls or emails about “updating your policy” or “verifying a claim” and contact Aflac using the phone number on your card, not links in messages. Watch medical bills and insurance statements for procedures you did not receive; dispute anything suspicious quickly.[8][9]
  • Nissan – customer info exposed via a vendor
    Nissan Motor Co. confirmed that servers managed by technology provider Red Hat were accessed without permission, exposing personal data for about 21,000 customers of Nissan Fukuoka Sales in Japan. The data includes names, addresses, phone numbers, email addresses, and sales‑related records, which could help scammers send convincing fake messages.
    What this means for you:
    This is a reminder that your data can be compromised through a company’s partners, not just the company you see on the bill or showroom. Be cautious of emails or texts that look like they are from a car dealer or service center about “urgent recalls” or payments; confirm through known phone numbers or the official website instead.[8][10]
  • Qantas and other big brands – leaked customer records
    A large cache of data allegedly stolen from Qantas, Australia’s flag carrier airline, was leaked after a ransom deadline passed, with attackers claiming to have personal information for about 5.7 million customers. The same criminal group says they accessed data from many other global brands using shared cloud tools, exposing names, contact details, and travel or customer records.
    What this means for you:
    Travel‑related details can be used for highly believable scams such as fake itinerary changes, refund offers, or loyalty‑point theft. Always manage bookings and loyalty points by going directly to the airline or hotel’s app or website, not through links in unexpected emails.[8]
  • Supply‑chain attacks – Red Hat and Oracle systems
    Security reports highlight that attackers are increasingly going after big software platforms, such as Oracle E‑Business Suite and systems managed by firms like Red Hat, then reaching many customer organizations at once. In some cases, this has led to sensitive data being stolen from several universities, media companies, and corporate customers through a single exploited vulnerability.
    What this means for you:
    For individuals and small businesses, this means you can be affected even if your own systems were never hacked directly. Small businesses should ask software and IT vendors how they handle security updates and data protection, and insist on written notification procedures if a breach happens.[8][11][12]

These cyber incidents show that attackers routinely go after businesses that offer the greatest reward while providing the least resistance, targeting businesses with critical data that is poorly defended. All businesses should assume at least one supplier, insurer, or tech vendor you use will eventually have a breach, and plan how you will respond (who to notify, how to monitor accounts, what to say to customers). Collect only the customer data you truly need, store it in as few systems as possible, and enable multi‑factor authentication and regular backups on those systems. Communicate clearly and quickly with customers after any incident; simple, honest explanations build more trust than silence or confusing technical language. Fundamental cyber security hygiene steps go a long way in protecting against attacks.


Citations:
[1] Christmas 2025: A Warning About Phishing Messages, AI-Driven … https://www.news4hackers.com/christmas-2025-a-warning-about-phishing-messages-ai-driven-scams-and-fake-offers/
[2] US small businesses are fighting off a wave of cyber attacks – ITPro https://www.itpro.com/security/us-small-businesses-are-fighting-off-a-wave-of-cyber-attacks
[3] December 2025 The Most Dangerous Time of the Year – 1Wire Fiber https://1wirefiber.com/business-data-services/network-optimization/cybercriminals-make-december-2025-the-most-dangerous-time-of-the-year/
[4] Accounting firm took over a year to inform users of data breach https://cybernews.com/security/sax-data-breach-quarter-million-exposed/
[5] VeraBank Data Breach Affects Thousands: Full Details https://www.claimdepot.com/data-breach/verabank-2025
[6] Data Breaches 2025: Biggest Cybersecurity Incidents So Far https://www.pkware.com/blog/recent-data-breaches
[7] VisionPoint Eye Center Data Breach Victims Benefit from $750,000 Settlement https://www.hipaajournal.com/visionpoint-eye-center-data-breach-settlement/
[8] List of Recent Data Breaches in 2025 – Bright Defense https://www.brightdefense.com/resources/recent-data-breaches/
[9] Aflac breach exposes personal and health data of more than 22M … https://siliconangle.com/2025/12/24/aflac-breach-exposes-personal-health-data-22m-people/
[10] Nissan says Red Hat breach affected thousands of customers https://www.cybersecurity-review.com/nissan-says-red-hat-breach-affected-thousands-of-customers/
[11] CLOP targets Gladinet CentreStack servers in large-scale extortion … https://securityaffairs.com/185875/cyber-crime/clop-targets-gladinet-centrestack-servers-in-large-scale-extortion-campaign.html
[12] Broadcom Targeted in Oracle E-Business Suite Breach – LinkedIn https://www.linkedin.com/pulse/broadcom-targeted-oracle-e-business-suite-breach-cl0p-ransomware-r4qmf

Discover more from BET-R Security Solutions

Subscribe now to keep reading and get access to the full archive.

Continue reading

search previous next tag category expand menu location phone mail time cart zoom edit close