Robin’s Newsletter #419

28 June 2026. Volume 9, Issue 26
Five Eyes urge cyber resilience focus. TfL Scattered Spider duo make guilty plea. Chinese firm unveils 'Mythos' level model.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 28th June 2026

  • Five Eyes cyber agencies urge businesses to improve cyber resilience
  • TfL attackers pleaded guilty to 2024 compromise
  • Klue compromise leads to Salesforce data access
  • Chinese company unveils Mythos-esque model
  • Hospital probing medical records access of crocodile attack child

Interesting stats

58% of claims are email-related business email compromise (BEC) and funds transfer fraud (FTF), while  $1 million, the average initial ransom demand (up 47%), and  70% involved both encryption and data exfiltration (“double extortion”), though  100% of UK claims were restored within ransom demands being paid, according to Coalition’s 2026 Cyber Claims Report (h/t Tony for the reminder on this one!)

Five things

  1. Five A-Eyes: Leaders of the Five Eyes cyber agencies have issued a joint letter (PDF) urging businesses to take swift action to up cyber resilience and advance “business continuity, market confidence, and long-term value”. To do this, they say that business leaders should understand and assess risk, prioritise foundational cyber security practices and controls, and empower cyber leaders with authority and resources. (I didn’t have anything to do with the, but that is exactly what Cydea helps organisations to do!) The action is needed because “cyber risk assumptions can become outdated in months, not years”, and the NCSC blog post goes on to point out that “Cyber risk can no longer be treated as a purely technical issue. This is a core business risk and leadership responsibility.”

  2. TfL: The two men behind a 2024 cyberattack against Transport for London have pleaded guilty this week to the incident that cost TfL £39 million. Owen Flowers, 18, from Walsall, and Thalha Jubair, 20, from east London, were both known to the police at the time and were part of the loosely affiliated Scattered Spider group. The National Crime Agency has called for more powers — so-called Cyber Crime Risk Orders (CCROs) — to use in cases like this. However, West Midlands Regional Cyber Crime Unit officers chose not to invite Flowers to the national Cyber Choices programme because he didn’t engage with officers during a visit and instead issued a cease-and-desist order. Given the evidence against the pair, it’s a sensible choice to plead guilty and avoid a lengthy trial, though one expert witness said: “They don’t seem to understand the consequences and there are real victims here losing their life savings in some case as well as corporations and their staff that are badly impacted”. (Side note, identifying and diverting talented young hackers is the problem that The Hacking Games is trying to solve.)

  3. Klue, a market research company, was compromised after attackers stole a credential from a 2022 pilot programme and used this to access ‘hundreds’ of the firm’s customers’ Salesforce CRM data. The affected customers include cyber outfits like Recorded Future, Huntress, Hacker One, Tanium, Snyk, and LastPass. Klue CEO Jason Smith said the company identified the breach on 12 June, with hack-and-leak group known as Icarus taking credit and Klue saying that the group is deleting their data (presumably a ransom has been paid). In the meantime, Klue’s customers should check their logs for indicators of compromise and rotate their integration credentials (Salesforce has disabled the Klue Integration following the breach).

  4. Mythos Madness: Chinese cyber company Qihoo 360 claims it’s built an AI vulnerability model that’s better than Anthropic’s Mythos. Introducing the model, CEO Zhou Hongyi described their approach as a “multi-agent swarm”, adding, “If the American approach is about cultivating a genius hacker, the 360 approach is about organizing a professional attack and defense team”. At the firm’s 14th Beijing Cybersecurity Conference, Zhou used the recent block of Mythos to foreign nationals as a reason for why China needs a sovereign capability “equivalent to a ‘cyber nuclear weapon’”. US authorities already sanctioned Qihoo 360 for supplying China’s military.

  5. See you later, Alligator: Cambridge University Hospitals (CUH) is investigating a potential data protection breach after up to 40 members of staff accessed the medical records of a three-year-old boy injured in a crocodile attack. The NHS trust has reported itself to the Information Commissioner’s Office. It’s an unusual story, sure to spark water-cooler curiosity, and props to them for having monitoring in place to detect and audit this type of access.

In brief

And finally

  • Using employee benefits and time off for phishing tests is a surefire way to lose credibility in your security programme, especially if it means your organisation’s CEO has to start giving media statements. That’s what Canadian healthcare outfit Newfoundland and Labrador Health Services learned the hard way this week. Ron Johnson, interim CEO, said, “We acknowledge the approach taken in this particular exercise was not appropriate, and we sincerely apologize to employees, physicians, and union representatives,” after a phishing test promised employees additional time off.
Robin
  Artificial Intelligence (AI) Sovereignty Transport for London (TfL) Cyber crime China