Cybersecurity · Thursday, 13 August 2026
01 · Briefing · what happened
This week's breaches became takeovers - too many accounts could reach too much
A year-long data theft through over-wide guest access, ransomware crews hunting the accounts with the broadest reach, and a firewall gang seizing wide access - all one lesson: a break-in's harm is capped by what the broken-in account can already reach.
351
victims in one ransomware campaign
across 334 organizations; 62% held a manager title or higher
$10M+
typical Gunra ransom demand
with five to seven days to pay
421
flaws in Microsoft's August patch
one already exploited before the fix existed
~2 yrs
UK records office breaches went unseen
three intrusions, thousands of people exposed
At a glance
- Attackers stole data from Salesforce and ServiceNow sites left with guest access set too wide - no password needed.
- Researchers named the year-long campaign 'City-Forum'; it hit telecom, finance, and public-sector organizations worldwide since March 2025.
- Zscaler found ransomware crews now hunt managers, not CEOs: 62% of one campaign's 351 targets held a manager title or higher.
- The prize is 'business privilege' - accounts that can approve payments and open HR, contracts, and customer records.
- The FBI, CISA, and South Korea warned about Gunra, a gang using Fortinet firewall flaws to seize wide access and demand over $10 million.
- Microsoft's August patch fixed 421 flaws, one already being exploited before a fix existed.
- The common thread: a break-in's damage is capped by what the broken-in account, role, or tool could already reach.
Forces in play
guest roles, manager accounts, and admin consoles reaching far past their job
crews study org charts to phish the account with the widest reach
splitting access so one break-in stays in one room - spreading slowly
421 Microsoft flaws in a month, plus gangs using flaws already known
How it unfolded
- Aug 11 FBI, CISA, and South Korea warn about Gunra ransomware
- Aug 11 Microsoft's August patch fixes 421 flaws, one exploited
- Aug 12 researchers detail the year-long City-Forum guest-access data theft
- This week Zscaler research: managers, not CEOs, are the prime ransomware targets
Where this points
Watch whether more companies audit what their guest roles and manager accounts can actually reach - the fix for all of this is narrower access, and it spreads slowly.
Full briefing
The account that could read everything
On Tuesday, security researchers detailed a data-theft campaign that ran for more than a year, which they call “City-Forum”
Guest access is what an anonymous visitor is allowed to see. On many of these sites it was set too wide. So the attacker pulled real records without stealing a single password
The tooling isn’t the point. A setting meant for the public could reach data meant for staff. Nobody picked a lock. The lock was set to “open for guests.”
Attackers hunt for the widest door, not the strongest one
A separate piece of research this week, from Zscaler’s ThreatLabz team, maps who ransomware crews - gangs that lock a victim’s files and demand payment - now go after
Rather than emailing the CEO, the attackers research a company’s reporting lines and pick the employees whose accounts touch the most
Same pattern, bigger blast radius
Microsoft warned this weekend that a China-linked crew it tracks as Storm-1175 began deploying new ransomware, StormEncryptor, on August 2
The same word - privileged - sits at the center of this week’s biggest ransomware alert. On Monday the FBI, CISA (the US cyber-defence agency), and South Korea’s police warned about Gunra, a gang built from leaked Conti ransomware code
Why narrow access is the whole defence
These stories look separate. They share a spine: a break-in’s damage is bounded by what the broken-into thing can reach. A guest role that could read staff records. A manager account that spanned the whole business. A console with god-mode over every client. When any one is compromised, its reach is the ceiling on the harm.
The defensive answer has a plain name: least privilege. Give every account, role, service, and tool only the access its job actually needs, and nothing more. The guest role reads what guests should read. The manager approves what that manager approves, not everything. The console reaches only the clients it must. Least privilege doesn’t stop the break-in - it traps the intruder in one room instead of handing over the building.
Two more this week show the cost of getting it wrong. A supply-chain attack means compromising one thing many others rely on. One this week poisoned a data feed used by WordPress plugin maker BdThemes to quietly create rogue admin accounts on affected sites
The patch pile, and the week’s other breaches
Microsoft’s August update was one of its largest ever: 421 flaws fixed, including one Windows flaw already being exploited before the patch existed
Elsewhere, a cyberattack on freight giant Ceva Logistics disrupted European retailers and may have exposed data belonging to customers of the Steam gaming platform
02 · Lesson · why it matters
Why a break-in becomes a takeover
The harm from a break-in isn't how the attacker got in - it's how far the account they broke into could reach.
How it works
- Every account, role, and tool is handed some access
- Handed more than the job needs, that extra just sits there
- Until a break-in - a phished login, a flaw, a poisoned update
- Then the intruder inherits everything that account could reach
- Narrow the access first, and the break-in stays trapped in one room
The twist
The damage from a break-in isn't set by how the attacker got in - it's set by how far the thing they broke into could already reach.
Where you've seen this
A house key
a cleaner needs the key to one door, not the master key to every room and the safe
A bank branch
a teller moves small sums; the vault needs two managers, so one bribed teller can't empty it
A ship's hull
watertight compartments mean one breach floods a section, not the whole vessel
A film studio
a day's extra gets a wristband for one lot, not the keys to the whole studio
The catch
Least privilege is friction - every extra check slows real work, so the pull is always to hand out broad access 'just to be safe,' which is how the reach creeps wide again.
Full lesson
Nobody picked the lock
This week, researchers described an attacker who spent more than a year quietly reading companies’ internal records. There was no clever break-in. The companies used systems - Salesforce, ServiceNow - that let anonymous visitors see a little. On many sites, “a little” was set too wide. The visitor’s pass opened doors meant for staff.
Think about what that means. The failure wasn’t the front door. It was how much a public setting could reach. The lock worked fine. It was just set to “open for guests.”
Attackers go for the widest door, not the strongest one
A second piece of research this week found something telling. Ransomware crews - gangs that lock your files and demand payment - have started skipping the CEO. They aim at managers instead.
Why a manager? Not because the account is powerful in a technical sense. Because it reaches far. A manager approves payments, reviews contracts, opens HR files, sees customer accounts. One login, and an attacker inherits all of it. The researchers gave it a name: business privilege. The value of an account, to someone who steals it, is simply the breadth of what it can touch.
The reach is the ceiling
Put these together and a pattern shows up, plain and hard.
A break-in’s damage is bounded by what the broken-into thing can reach. A guest setting that could read staff records. A manager account that spanned a whole company. A remote console with what one report called “god-mode” - one screen that ran thousands of client machines at once. In each, the harm wasn’t decided by how the attacker got in. It was decided, in advance, by how far that door already opened.
The reach is the ceiling on the harm. And most of the time, nobody chose that ceiling on purpose. It just drifted wide.
The defence has a plain name
The answer isn’t a taller wall. Walls fail; something always gets in. The answer is narrower doors.
Security people call it least privilege. Give every account, every role, every tool only the access its actual job needs - and nothing more. The guest reads what guests should read. The manager approves what that manager approves, not everything. The console reaches only the machines it must, split so one break-in can’t touch them all.
You already know the shape of this. A bank teller can move small sums; emptying the vault takes two managers and a second key. A cleaner gets the key to one office, not the master key to the building and the safe. A ship has watertight compartments, so one hole floods a section, not the whole hull. None of it stops the accident. All of it decides how big the accident gets.
Least privilege doesn’t stop the break-in. It traps the intruder in one room instead of handing over the building.
Why the doors keep drifting open
Here’s the honest catch. Narrow access is a nuisance.
Every extra check slows real work. Someone needs a file “just this once,” and it’s faster to grant broad access than to scope it and remember to take it back. Convenience and safety pull in opposite directions, and convenience wins the day-to-day. So access accretes. A permission granted for one project outlives it. A role built for five people ends up used by fifty. None of it is malice - it’s the path of least resistance, quietly widening, until a break-in finally cashes it in. The arrangement that made yesterday’s work smooth is the one that hands over the building today.
You are inside this
This isn’t only a problem for corporate IT departments. You live in the same shape.
Your email account is a master key. It can reset the password on nearly everything else you own - so whoever holds it holds all of you, not just your inbox. The app you let see “all your contacts” or track your location “always” is carrying more of you than its job needs. The single question that runs through all of it - does this really need to reach that? - is the whole defence, at every scale.
And the companies holding your records are answering that same question, quietly, on your behalf. When one of them leaves a guest setting too wide, you are the staff records on the other side of it.
What seeing this leaves you with
You can’t watch every door. Neither can the people who run the systems you depend on - the admins, the regulators, the app makers. That’s not their failure or yours; a system has more openings than any one seat can see.
So the safest system was never the one that keeps everyone out. It’s the one where a break-in stays small - where the reach was narrowed before anyone got in. The break-in is somewhere in the future, probably unavoidable. The reach is the part still up for grabs today. And none of us ever fully knows how far a single key opens until it’s turned.
03 · Lab · your turn
Set the reach
Rehearse how narrow access traps a break-in in one room, while broad access turns one stolen login into a takeover.
04 · Hope · carry this
The good news: the fix needs no new invention. Every time someone narrows what a thing can reach - a manager, an admin, you with an app - the next break-in gets smaller.
More from Cybersecurity