Cyber News: Week Ending January 9, 2026

It’s the first full week of 2026, and cybercriminals have been busy making sure their New Years Resolutions of spreading malware and stealing valuable information are off to a great start by deploying some new tactics, as well as turning to some reliable old tricks. In this post, we’ll provide actionable tips on how to protect your personal and business data from the latest threats.

1. Smarter Phishing & “Quishing” Scams
Attackers are increasingly impersonating banks and other financial companies, sending highly realistic messages and even using AI to write them, making fake emails and texts much harder to spot. The FBI also warned that a North Korean-linked group is embedding malicious QR codes in targeted emails (“quishing”) to steal logins when people scan them.

BET-R Actions: Do not trust links or QR codes in unsolicited emails, texts, or social posts, especially for payments, password resets, or account verification. Open your browser and type the site address yourself (or use a saved bookmark) instead of tapping/scanning from a message.​ Turn on multi-factor authentication (a code via app or text) on email, banking, payroll, and key business tools so stolen passwords alone are not enough.

2. Ransomware Targeting Smaller Businesses
New data shows ransomware groups are going after small and mid-sized companies more than big enterprises, betting that they lack defenses and will quietly pay to get back critical files. Around a third of small-business ransomware cases start with stolen or reused passwords, and many attacks exploit known security gaps that were never fixed.

BET-R Actions: Use a password manager and require unique, strong passwords for email, accounting, remote access, and admin accounts; never reuse key passwords. Turn on automatic updates for computers, phones, routers, and business apps so known security holes get patched without you having to remember. Keep at least one backup that is offline or in a separate cloud account, and test that you can restore it; this can let you recover without paying ransom.

3. WIRED Magazine Subscriber Data Leak
Data for roughly 2.3 million WIRED magazine subscribers was exposed, including email addresses and some personal details, increasing the risk of targeted phishing and identity fraud attempts against those users. Passwords and payment data were reportedly not included, but the attacker claimed to hold far more data from related brands and the leaked emails were added to breach-checking sites.​

BET-R Actions: If you have subscribed to WIRED or other Condé Nast titles, expect more “too specific to be spam” emails; treat unexpected invoices, support messages, or prize notices as suspicious. Do not reuse email account passwords anywhere else; if you have, change your primary email password and turn on multi-factor authentication right away. Use a breach-checking service (such as Have I Been Pwned) to see if your email appears in known leaks, and if it does, change passwords linked to that address.​

4. AI Is Supercharging Everyday Scams
Experts warn that AI tools are making it trivial for criminals to mass-produce polished scam emails, fake support chats, and even realistic voice or video impersonations that can trick staff and customers. This shift means “gut feel” based on bad spelling or awkward wording is no longer enough to recognize fraud.

BET-R Actions: Create a simple “out-of-band” rule: before transferring money, changing payroll info, or sharing sensitive data, confirm using a different channel (e.g., call a known number, not the one in the email).​ Train staff to pause when something feels urgent or secret (“Do this now and don’t tell anyone”); urgency is a red flag that should trigger extra checks. Limit who can approve payments and admin changes, and require at least two people to sign off on large transfers or new vendor accounts.

START SMALL: Simple Cyber Hygiene Moves for 2026

Security pros are urging businesses this year to stop “waiting and seeing” and instead put a few basic protections in place, because nearly half of recent breaches trace back to simple human mistakes like clicking bad links or ignoring updates. Even with tight budgets, focusing on a short list of high-impact basics dramatically cuts risk for both individuals and small businesses.

High-impact steps to take this week

  • Keep a written “incident checklist” (who to call, what to unplug, where backups are) so you are not guessing in the middle of a crisis.
  • Turn on updates and restart devices at least weekly so security patches apply properly.​
  • Use a reputable antivirus/endpoint protection on all work computers and phones that handle business email or files.

Recent Trends and Incidents

Several organizations started 2026 by disclosing (or were reportedly linked to) cyber incidents, ranging from healthcare and insurance to engineering and tech services. Below are a few examples of breaches that could impact you or your organization, and lessons learned that can help protect your data from similar threats.​

  • Ledger / Global-e e‑commerce breach
    Security reports describe a major breach at Global‑e, an e‑commerce provider used by multiple brands, including crypto wallet company Ledger. Names, emails, addresses, phone numbers, and order details were reportedly exposed, but not passwords, card numbers, or crypto seed phrases.​
    What this mean for you: Expect more targeted scam emails or texts that correctly reference past orders or personal details to build trust.​ Do not click links in messages about orders; instead, log in via the official website or app and check order history there.​ If you bought from Ledger or other brands using Global‑e, change your account password and enable multi‑factor authentication (MFA) where available.​
  • Blue Shield of California potential data breach
    Blue Shield of California announced a potential privacy breach affecting members’ protected health information after an incident involving a third party handling data. The notice indicates that personal and health-related details may have been exposed, and affected members are being contacted.​
    What this means for you: Watch for health‑related scams, such as fake insurance calls or emails asking to “verify” your coverage, Social Security number, or payment info.​ Use the free credit monitoring or identity protection services offered, and place a fraud alert or credit freeze if you see anything suspicious. Log in only through the official insurer site or app; never share ID numbers or medical details over unsolicited calls or emails.​
  • The Structures Group ransomware claim
    The ransomware group Sinobi claimed responsibility for an attack on The Structures Group, a U.S. engineering firm, threatening to leak sensitive company data if negotiations are not started. Public reports focus on the claim and extortion threat rather than any confirmed data release so far.​
    What this means for you: Ransomware gangs are targeting professional services and engineering/consulting firms, not just giant corporations. Protect shared project files and client data with good backups kept offline or in a separate cloud account so work can continue even if systems are locked. Use unique, strong passwords and MFA on email, VPN, and remote‑access tools, which are common entry points for this kind of attack.​
  • Oracle Health–linked healthcare system breach
    Multiple U.S. health systems reported being affected by a data breach linked to Oracle Health (formerly Cerner), a major electronic health records vendor. Impacted hospitals and health systems are notifying patients whose information may have been exposed, which may include medical and personal details.​
    What this means for you: Even if your local clinic is small, its use of big vendors like Oracle Health means your records can be caught up in large‑scale incidents. If you receive a breach notice, carefully review your medical bills and insurance explanations of benefits for services you did not receive. Small medical practices should review vendor contracts and ensure data‑sharing partners must notify them quickly when an incident occurs.​

Other reported January breaches (early list)
Breach trackers and legal notices list several other January incidents, including attacks affecting a European Space Agency system and multiple private companies like Eros Elevators, Sugawara Laboratories, and CSV Group. Many of these involve theft of names, contact details, and sometimes financial or ID numbers, which can fuel phishing, fraud, and identity theft.

DO NOT REUSE PASSWORDS; a leak at one company should not unlock your email, bank, or payroll accounts. Turn on MFA wherever it is offered, especially for email, banking, healthcare portals, and key business apps. Treat any unexpected message referencing a real company you use (bank, insurer, store) as suspicious until you confirm it through the official website or phone number.


Citations:

2.3M WIRED Subscribers Exposed in Condé Nast Leak

Cyber hygiene tips to cut ransomware risk in 2026

Technology Insider January 2026 – Merit Technologies

What Every Company Needs To Know About Cybersecurity In 2026

FBI warns of attacks by North Korean cyber threat group using malicious QR codes | AHA News

Privacy and Cybersecurity Client Alert | January 2026 | 2026 Privacy Compliance Uplifts and Enforcement Risks | Shook, Hardy & Bacon L.L.P. – JDSupra

Ransomware Statistics 2026 | VikingCloud

What small businesses need to know about new cyber threats thanks to AI

Data Breaches Digest: Data Breaches Digest – Week 1 2026

BDSLCCI Framework 2026: Expanded Cybersecurity Tools and Guidelines for Small and Medium Businesses – Knox News | The Knoxville News-Sentinel

Cybersecurity Threats January 2026: Attackers Shift to Trust Abuse

January 5, 2026: Blue Shield of California Notifies Members of Potential Data Breach | Blue Shield of California | News Center

The Data Breach Brief: Week of January 7th, 2026 | 1/7/2026

Sinobi Ransomware Attack on The Structures Group – DeXpose

13 health systems affected by Oracle Health data breach – Becker’s Hospital Review | Healthcare News & Analysis

Top data breaches of January 2026 (so far) (updated daily) – SharkStriker

Latest Data Breaches and Most Recent Data Breach Incidents

Moody’s forecasts growing AI threats, regulatory friction for 2026 | Cybersecurity Dive

Fifth of Breaches Take Two Weeks to Recover From – Infosecurity Magazine

5th January – Threat Intelligence Report – Check Point Research

The biggest cyber attacks of 2025 and what they mean for 2026

Cybersecurity Predictions 2026: The Hype We Can Ignore (And the Risks We Can’t)

Cyber News Roundup – January 2nd 2026

Data breach at Covenant Health last spring much larger than originally reported by officials | Maine Public

Top 10 Ransomware Attacks of 2025

Discover more from BET-R Security Solutions

Subscribe now to keep reading and get access to the full archive.

Continue reading

search previous next tag category expand menu location phone mail time cart zoom edit close