Skip to content
All resources
Cybersecurity Intel · № 04 · 16 February – 1 March 2026

They logged in: the fortnight attackers stopped breaking in

A vishing crew compromises CarGurus, Wynn Resorts and Figure without a single exploit. France's national bank registry is read for 16 days with one stolen credential and no MFA. And a CVSS-10 Cisco SD-WAN bypass triggers a federal emergency directive with 48-hour deadlines.

Published 2 March 2026 By Blacklight Threat Intelligence Classification TLP:CLEAR · Public
12.4M
CarGurus accounts exposed after voice-phishing of SSO credentials
1.2M
French bank accounts viewed via one stolen credential with no MFA
10.0
CVSS score of the Cisco SD-WAN auth bypass, exploited since 2023
9 days
All 35 UMMC clinics closed statewide by a single ransomware intrusion

Executive summary

  • Attackers logged in rather than broke in. The fortnight's biggest breaches, CarGurus, Wynn Resorts and France's FICOBA bank registry, all began with a valid credential: vishing of SSO logins in the first two, a stolen civil-servant account with no MFA in the third.
  • The network perimeter itself became the exploit. A CVSS-10 authentication bypass in Cisco SD-WAN controllers, exploited quietly since 2023, forced CISA to issue an emergency directive giving federal agencies 48 hours to inventory and patch.
  • Healthcare paid the availability price. Ransomware closed all 35 University of Mississippi Medical Center clinics for nine days, and healthcare absorbed roughly a third of February's publicly disclosed ransomware incidents.

Key findings

19 February 2026 Ransomware · T1486

Ransomware shuts all 35 UMMC clinics statewide for nine days

Ransomware detected in the early hours of 19 February took down the University of Mississippi Medical Center's network, including its Epic electronic health record system, closing all 35 clinics across the state and pushing staff to pen and paper. Clinics reopened on 2 March after nine days; UMMC worked with the FBI and CISA and communicated directly with the attackers.

20 – 21 February 2026 ATT&CK T1566.004

Vishing crew breaches CarGurus, Wynn and Figure without one exploit

An extortion crew published 12.4 million CarGurus records, demanded 1.5 million dollars from Wynn Resorts over roughly 800,000 employee records, and took around a million customer records from Figure Technology Solutions. Every intrusion began the same way: operators posing as IT support on the phone, harvesting SSO credentials and MFA codes. Over 100 organisations have been hit by the wider campaign.

18 – 19 February 2026 ATT&CK T1078

France's national bank registry read for 16 days with one credential

France's Ministry of the Economy disclosed that an intruder used a civil servant's stolen credentials, on an account with no two-factor authentication, to query the FICOBA national bank account registry for 16 days. Data for roughly 1.2 million accounts was viewed, including IBANs, holder names and addresses, from a registry tracking nearly 300 million accounts.

25 February 2026 CVE-2026-20127 · KEV

CVSS-10 Cisco SD-WAN bypass triggers emergency directive ED 26-03

CISA, the NSA and international partners published joint guidance on global exploitation of Cisco SD-WAN systems via an unauthenticated authentication bypass granting admin privileges, reportedly exploited since 2023 for long-term persistence. Emergency Directive ED 26-03 gave US federal agencies 48 hours to inventory and patch, a pace private enterprises should mirror for controller-class infrastructure.

17 – 24 February 2026 KEV · Regulation

Chrome's first exploited zero-day of 2026; UK resilience bill advances

CISA added six KEV entries across the fortnight, including Chrome's first actively exploited zero-day of the year (CVE-2026-2441) and two Roundcube webmail flaws used for initial access. In parliament, the UK Cyber Security and Resilience Bill completed committee stage, expanding scope to managed service providers and tightening incident reporting ahead of expected Royal Assent this year.

The broader pattern

  • Identity is the initial-access vector of the fortnight. Vishing of SSO logins and a single un-MFA'd account did more damage than any exploit chain; help-desk verification and phishing-resistant MFA are now frontline controls.
  • Network management planes are crown-jewel assets. An SD-WAN controller bypass exploited for years shows the devices that define the perimeter need the same monitoring, patch SLAs and behavioural baselines as the assets behind them.
  • Valid-credential intrusions leave behavioural traces, not signatures. A registry account querying 1.2 million records, or an admin logging in from new infrastructure, only surfaces if identity activity is baselined per account.

Sector lens

Healthcare
UMMC's nine-day statewide closure is the availability cost of a single intrusion, and healthcare absorbed roughly 31% of February's disclosed ransomware incidents. Machine-speed containment on endpoint alerts is the difference between one host and 35 clinics.
Financial services
The FICOBA breach shows registry and back-office accounts with broad read access are prime targets. Baseline per-account query volumes and enforce MFA on every privileged system, including the boring internal ones.
Government
ED 26-03's 48-hour inventory-and-patch deadline for SD-WAN is the clearest signal yet: treat network controllers as critical assets with emergency SLAs, not routine infrastructure.
Hospitality & gaming
The Wynn Resorts extortion shows employee HR data, salaries and SSNs is as monetisable as guest data, and the way in was a phone call to the help desk.

Suggested priorities to consider

Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.

01

Inventory and patch Cisco SD-WAN controllers now. CVE-2026-20127 is CVSS 10.0, on KEV, and was exploited for years before disclosure; treat exposure as presumed and hunt retroactively.

02

Harden the help desk against vishing. Require call-back verification and manager confirmation for any credential or MFA reset; the fortnight's three biggest breaches started with a phone call.

03

Enforce phishing-resistant MFA on every privileged and registry account. One un-MFA'd civil-servant login exposed 1.2 million bank accounts over 16 days.

04

Baseline query and export volumes per identity on data-rich internal systems. Valid-credential abuse produces no exploit signature; anomalous per-account volume is the earliest tell.

05

Rehearse the paper fallback for clinical and operational continuity. UMMC ran 35 clinics on pen and paper for nine days; the plan only works if it has been drilled.

These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.

How Blacklight handles this

Every major intrusion this fortnight rode a valid login, not malware. Blacklight baselines behaviour per identity across SSO, SaaS and network management planes, so a help-desk-reset account authenticating from new infrastructure, a registry login querying at 100x its normal volume, or an SD-WAN admin session that matches a KEV exploitation pattern is investigated and contained autonomously, with the full reasoning trail ready for your team.

Book a Demo

Sources & methodology

Primary public sources this issue: CISA Known Exploited Vulnerabilities catalog and Emergency Directive ED 26-03 (February 2026) · joint CISA/NSA advisory on Cisco SD-WAN exploitation (25 February 2026) · Google Chrome security release notes (13 February 2026) · public breach disclosures and security-press reporting (BleepingComputer, SecurityWeek, The Record, The Register), 16 February – 1 March 2026 · BlackFog State of Ransomware, February 2026 · UK Parliament, Cyber Security and Resilience Bill progress · MITRE ATT&CK v15 for technique mapping.

Methodology. Findings are compiled from public reporting and Blacklight Threat Intelligence monitoring for the stated window, mapped to MITRE ATT&CK where applicable. Aggregate platform observations, where cited, are anonymised across the Blacklight customer base and never identify a customer environment. Corrections: intel@blacklightai.com.

Related reading

Blacklight AI · Cybersecurity Intel · № 04 TLP:CLEAR
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.