Skip to content
All resources
Cybersecurity Intel · № 07 · 30 March – 12 April 2026

Breached upstream: the fortnight attackers arrived as trusted traffic

One poisoned open-source scanner cascades into a tier-1 network vendor and the European Commission. Ransomware at a single software supplier disrupts most Dutch hospitals. And a state actor turns thousands of home routers into a silent credential-harvesting layer.

Published 13 April 2026 By Blacklight Threat Intelligence Classification TLP:CLEAR · Public
80%
Of Dutch hospitals run the EHR platform hit by ransomware on 7 April
7.7TB
Of police records leaked from one unprotected file-transfer system
120+
Countries touched by a state actor's router DNS-hijacking network
24h
Fastest observed access-to-ransomware time in one crew's operations

Executive summary

  • Attackers broke in upstream and arrived as trusted traffic. Credentials stolen via a trojanised open-source security scanner were used to clone 300+ private repositories at a tier-1 network vendor and take 340 GB from the EU's web-hosting platform across 71 organisations.
  • One vendor became a national single point of failure. Ransomware at ChipSoft, whose EHR platform serves roughly 80% of Dutch hospitals, forced patient-portal disconnections across the country, with the crew claiming around 100 GB of stolen data.
  • The defence window is compressing to hours. One crew was documented exploiting two flaws about a week before each was publicly disclosed and moving from access to ransomware within days, sometimes 24 hours, while a state actor quietly ran DNS hijacking through 18,000+ compromised routers in over 120 countries.

Key findings

7 – 8 April 2026 Ransomware · T1486

Ransomware at one EHR vendor disrupts most Dutch hospitals

ChipSoft, whose HiX electronic health record platform serves roughly 80% of hospitals in the Netherlands plus Belgian institutions, was hit by ransomware, forcing it to disable portal and mobile connections while eleven hospitals disconnected patient portals as a precaution. The crew behind it claimed roughly 100 GB of stolen data. Healthcare's dependency graph is the vulnerability.

1 – 3 April 2026 ATT&CK T1195.002

Poisoned scanner cascades into Cisco source code and the European Commission

Credentials stolen via trojanised releases of the Trivy open-source scanner were used to clone more than 300 private repositories at Cisco, including unreleased AI product source, and to breach the EU's Europa hosting platform: roughly 340 GB across 71 client organisations, entered weeks earlier with a stolen cloud API key. One upstream compromise, two continents of blast radius.

7 – 8 April 2026 Exposure · T1567

7.7 TB of police records leaked from an unprotected transfer system

An extortion group published over 337,000 files taken from a third-party discovery-transfer system at the Los Angeles City Attorney's Office: officer personnel and disciplinary records, internal-affairs investigations, unredacted complaints with witness names, and medical records. The system reportedly lacked password protection because outside counsel needed access. Convenience became the breach.

6 April 2026 Zero-days · T1190

Ransomware crew documented exploiting flaws before public disclosure

Vendor research detailed a China-based, financially motivated actor chaining zero-day and n-day exploits against internet-facing systems, including mail and managed-file-transfer platforms, each exploited about a week before public disclosure, then moving from access to data theft and ransomware within days, in some incidents 24 hours. Heavy impact fell on healthcare, education and professional services.

7 April 2026 ATT&CK T1557

State actor's router botnet ran DNS hijacking across 120+ countries

A joint industry-government disclosure exposed a Russian military-linked campaign compromising consumer and small-business routers since at least May 2025 to hijack DNS and harvest credentials through adversary-in-the-middle nodes: 18,000+ unique IPs at peak, 200+ organisations affected, with foreign ministries and cloud providers among the targets. The infrastructure between your users and your cloud is attack surface.

The broader pattern

  • Software supply chain is the initial access of the quarter. A security tool's own update channel handed attackers CI/CD credentials that opened a network vendor and an EU institution; pin, verify and monitor what your pipelines pull.
  • Vendor concentration is a clinical risk. When one EHR supplier serves 80% of a country's hospitals, that supplier's SOC is effectively national infrastructure; contractually demand detection evidence, not just uptime.
  • Pre-disclosure exploitation breaks patch-first defence. When flaws are worked a week before the CVE exists, behavioural detection on internet-facing systems is the only control that fires in time.

Sector lens

Healthcare
ChipSoft is the sector's concentration-risk case study: your continuity plan must cover your EHR vendor's ransomware event, not just your own, including portal-down operations and paper fallbacks.
Government & public sector
The LAPD leak and the EU platform breach both rode third-party systems. Discovery-transfer tools, hosting platforms and case-management vendors carry your most sensitive records with the least of your controls.
Manufacturing & technology
300+ cloned source repositories at a tier-1 vendor show R&D theft riding supply-chain access; treat CI/CD credentials and code hosts as crown jewels with behavioural monitoring.
Connected & IoT
Thousands of consumer routers became a state actor's interception layer. Remote-work traffic transits equipment nobody patches; enforce DNS-over-HTTPS and certificate pinning so hijacked resolvers surface as anomalies.

Suggested priorities to consider

Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.

01

Audit what your CI/CD pipelines pull, and pin it. The scanner compromise spread through trusted tooling; version-pin dependencies, verify signatures and alert on new outbound destinations from build systems.

02

Rotate credentials that ever lived in pipelines or repositories. Stolen CI/CD and API keys drove both marquee breaches; assume historic exposure and rotate, then monitor the old keys for attempted use.

03

Demand a ransomware-readiness statement from your EHR and core SaaS vendors. Concentrated vendors are your availability risk; ask for their containment SLAs and test your portal-down procedures.

04

Inventory third-party file-transfer and discovery systems holding your data. An unprotected transfer tool leaked 7.7 TB of police records; anything reachable without authentication is already public, it just has not been published yet.

05

Put behavioural detection on internet-facing mail, MFT and edge systems. With exploitation preceding disclosure, the signature does not exist yet; anomalous process, egress and identity behaviour is the tell.

These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.

How Blacklight handles this

When the attacker arrives as your scanner's update, your vendor's session or your router's DNS, the question is not whether the perimeter held but whether anything noticed the behaviour change. Blacklight baselines every identity, pipeline and egress path it ingests, so a build system cloning at 50x its normal rate, a vendor account touching new data, or resolver traffic shifting to new infrastructure is investigated and contained autonomously, reasoning trail included.

Book a Demo

Sources & methodology

Primary public sources this issue: CISA Known Exploited Vulnerabilities catalog (entry of 6 April 2026) · CERT-EU statement on the Europa platform breach (3 April 2026) · Dutch healthcare CERT (Z-CERT) confirmation of the ChipSoft incident · Microsoft threat-intelligence reporting of 6 April 2026 · joint industry-government disclosure on router DNS hijacking (7 April 2026, incl. UK NCSC) · public breach disclosures and security-press reporting (The Record, TechCrunch, BleepingComputer, SANS ISC), 30 March – 12 April 2026 · Poland KSC Act commentary · MITRE ATT&CK v15. Attacker-claimed figures are labelled as claims.

Methodology. Findings are compiled from public reporting and Blacklight Threat Intelligence monitoring for the stated window, mapped to MITRE ATT&CK where applicable. Aggregate platform observations, where cited, are anonymised across the Blacklight customer base and never identify a customer environment. Corrections: intel@blacklightai.com.

Related reading

Blacklight AI · Cybersecurity Intel · № 07 TLP:CLEAR
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.