Robin’s Newsletter #399

8 February 2026. Volume 9, Issue 6
Italy repels Winter Olympics DDoS attacks. Questions linger over Salt Typhoon repsonse. 'Vast' Asian cyber-espionage campaign.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 8th February 2026

  • Italy repels Winter Olympics DDoS attacks
  • US senator questions telco response to Salt Typhoon
  • ‘Vast’ Asian cyber-espionage campaign unearthed
  • Russian group jumped on Office vuln in <48 hours
  • UK investigating five breaches of cyber sanctions

Interesting stats

£7,500 (~$10,200) payout will be made to all Police Service of Northern Ireland (PSNI) employees affected by the organisation’s 2023 data breach. 

£260 million ($354M) total cost from Jaguar Land Rover’s 2025 cyber incident, up from  £196 million last quarter, according to company statements. The carmaker has not touched the £1.5 billion government-backed loan.

Five things

  1. Winter Olympics: Italian authorities say they have repelled a series of “Russian origin” cyberattacks against, including diplomatic missions, hotels and facilities connected with the games. France 24 cites around 120 targets of DDoS attacks, claimed by the pro-Russian NoName057(16) group as “punishment” for Italy’s support of Ukraine. The IOC banned Russia from participating in the games. The Olympics are high-profile, high-stakes events for the host nation, and extensive planning, preparation, and monitoring will be in place to ensure the event proceeds without major incidents. Physical sabotage against railway targets seems to have been more effective.

  2. Salt Typhoon: US Senator Maria Cantwell is calling for the CEOs of AT&T and Verizon to appear before Congress and answer questions about their firms’ response to the China-linked Salt Typhoon group’s compromise of their telecommunications networks. Cantwell says both firms have “chosen not to cooperate” with requests for documentation to back up claims that their networks are now secure. An independent review conducted by the Cyber Safety Review Board was left unfinished when the Trump administration disbanded the board, and, latterly, FCC chair Brendan Carr rescinded regulations that enforced controls such as multi-factor authentication. Also this week, the Norwegian Police Security Service said that Salt Typhoon had compromised devices in Norwegian organisations as part of its National Threat Assessment (PDF)

  3. Diaoyu: Palo Alto Networks has uncovered a ‘vast’ cyber espionage campaign based in Asia. Security researchers say the operation breached the systems at 70 institutions across 37 countries, and conducted reconnaissance in 155 countries. This level of activity is what you would expect of a national-scale intelligence agency. While Palo also says the scale is “alarming”, what I think is remarkable here is that it’s been detected and tied together. While careful not be drawn on specific attribution, one of the puzzle pieces is metadata on a file named “diaoyu”, the Chinese word for phishing, oh, and one large Asian power is also not the target of reconnaissance. I’ll let you join the dots:

Countries targeted by ‘TGR-STA-1030’ reconnaissance (Source: Palo Alto)

  1. Microsoft Office: Security researchers are warning that it took Russian-linked threat groups less than 48 hours to start exploiting a vulnerability in Microsoft Office after an unscheduled update was released last month. This is a tight time window for organisations to react. However, it’s unclear whether the urgent nature of the update drew attention and prompted a rapid response from attackers, or was deployed urgently because Microsoft got wind of a potential forthcoming campaign. The APT28/Fancy Bear group used CVE-2026-21509 (7.8/10; advisory) to bypass local security features as part of a spear-phishing campaign targeting nine Eastern European countries.

  2. Cyber sanctions: The UK is investigating five potential breaches of sanctions applied to foreign cyber actors. All five investigations involve financial services firms, according to a freedom of information request filed by Recorded Future News to HM Treasury’s Office of Financial Sanctions Implementation (OFSI). Investigations shouldn’t be unexpected — the sanctions were introduced to deter payments to hostile and criminal groups — and so may typically be encountered if or when considering making ransom payments. Regulators face limited resources and have had their hands busy with those applied to Russia following the invasion of Ukraine, but this is a sign that cyber-related sanctions have not been forgotten. Civil penalties for FS firms that breach sanctions can be £1 million or 50% of the value of the breach, whichever is higher. At the same time, criminal cases have no such cap, and senior managers and directors can face up to seven years in prison. Food for thought for any board unlucky enough to find itself on the unfortunate end of an extortion attempt.

In brief

And finally

Robin
  Olympics Russia Salt Typhoon Norway China Cyber-espionage Sanctions