- HX Weekly by Hexagon Center
- Posts
- They’re back, breaches.
They’re back, breaches.
The first week of 2026 saw significant breaches targeting critical infrastructure and international scientific organizations. A 139 GB data leak from engineering firm Pickett and Associates exposed sensitive LiDAR and design files for major U.S. utility providers. The healthcare and retail sectors faced renewed pressure as ManageMyHealth reported a breach affecting 126,000 users and Ledger disclosed a third-party leak of customer order details.
Your quick weekend update and reminder.
☝️ TWA
Breaches are back in the news
This week’s cybersecurity news underscore a persistent shift toward targeting supply chains and unpatched external vulnerabilities to gain high-stakes access. Similarly, failing to enable multi-factor in your accounts explains this tragedy |
🤷♀️ What now?: Enable multi-factor authentication (MFA) and stay away from passwords, if possible.
📰 Headline Highlights
Sedgwick confirms cyber incident affecting its major federal contractor subsidiary
Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign
DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide
Kimwolf Android Botnet Infects Over 2 Million Devices via Exposed ADB and Proxy Networks
Illinois state agency exposed personal data of 700,000 people
Major Data Breach Hits Company Operating 150 Gas Stations in the US
Despite not being surprised by the numerous data breaches observed this week, we were not anticipating their occurrence. In fact, we intended to discuss the cyber aspect of Venezuela, but it is satisfactory that it has been included in the “Look Out” and “Must Read” sections.
Hexagon Center got a new logo. It was released on January 7 and quickly published to the front page of our website. Check it out at hexagoncenter.org.
HOUSEKEEPING
Glossary/Legend:
Agentic AI - autonomous artificial intelligence systems that can perceive their environment, reason, plan, and take actions independently to achieve complex goals with minimal human intervention, moving beyond simple command-response to proactive, goal-oriented behavior.
LLM or Large Language Model - an advanced AI trained on vast text data to understand and generate human-like text for tasks like chatbots and content creation.
Parked Domain - a registered web address (URL) that isn't actively linked to a full website but serves as a placeholder, often showing a generic page or ads, used to reserve the name for future development, protect a brand, or generate passive income from type-in traffic. It's like buying a piece of land but not building a house on it yet.
Holistic security - a comprehensive strategy that integrates various protection layers—physical, digital, psycho-social, and organizational—to safeguard individuals, communities, or systems, recognizing that true security involves overall well-being, not just isolated technical defenses.
Personal Identifier - A unique word or phrase shared exclusively with an individual or a group, serving as a means of identification and affirmation within the established relationship. It is recommended that 2 or more Personal Identifiers be established per person.
Malware (short for malicious software) - refers to any intrusive software developed by cybercriminals (often called hackers) to steal data and damage or destroy computers and computer systems.
Ransomware - A type of malware that locks or encrypts a victim's files and demands a ransom payment to unlock and decrypt them. Ransomware can infect a variety of devices, including computers, smartphones, printers, and more.
Spread cybersecurity culture
Do you have any suggestions on how we can further share this newsletter? Tell your friends and family about us by sharing with them the Hexagon Center official website:
View archives at hxweekly.beehiiv.com
Even though we aim to provide you the most current and critical information to keep you safe, threat actors work 24/7 and this newsletter publishes only once a week. Even though we are available via a hotline, it is crucial that you stay up to date via other sources as well to be informed on how you may be at risk.
You may reply to this newsletter or email us at
[email protected]
Send us any questions or things you want to talk about. Please share some fun facts with us. We welcome feedback and suggestions.
Hexagon Center is formed as a nonprofit corporation in California for public benefit,
and is tax-exempt under section 501(c)(3) of the Internal Revenue Code.
DISCLAIMER
Cybersecurity is an ever-changing field, and threats may evolve. While Hexagon Center strives to provide accurate and timely information, we cannot guarantee absolute security. Users are responsible for implementing their security measures and staying informed about the latest cybersecurity developments. Hexagon Center is not responsible for any cyber or scam attacks by our readers. HX Weekly tips are advice are not official positions of Hexagon Center nor is Hexagon Center responsible for its content.
Content of this newsletter is not an official representation of Hexagon Center.







Reply