CTI Daily Brief: 2026-08-22
title: Banking Trojans, Data Sales Surge as 70 Exposure Events Hit Global Targets description: Daily brief: 220 events, 70 data exposure incidents. Banking malware Manic, Grandoreiro, ToxicPanda 2.0 active. US, India, Indonesia top victim countries. keywords: ransomware, data breach, banking trojans, Grandoreiro, threat actors, data leak, CoupDeGrace
Summary
Today's threat landscape is defined by a high volume of alleged data exposure events, with 70 of 220 tracked incidents involving breaches or leaks. The pattern is not one of sophisticated, targeted intrusions but rather a broad, opportunistic churn of data sales and small-to-mid-sized organizational compromises. Defenders should note the significant concentration of activity against the US, India, and Indonesia, and the prevalence of actors offering databases for sale on forums, suggesting a mature underground economy for stolen credentials and personal records. The simultaneous activity of Latin American banking trojans adds a layer of active financial fraud risk that complements the data theft narrative.
Today's developments
The day's most significant incident stream involves multiple alleged data breaches and leaks across a wide range of sectors. CoupDeGrace and CoinbaseCartel were the most active actors, with 13 and 12 events respectively, though their specific targets are not all detailed in the critical list. Among the notable alleged incidents:
- Financial sector focus: Actors claim breaches at Qatar National Bank (Qatar, Banking), NinjaTrader Group (US, Financial Services), and CoinCodex (Financial Services). A separate actor claims to be selling a database of US credit card records, while another alleges a sale of 10 million US citizen records.
- Government and public sector hits: Alleged breaches include Taiwan's Judicial Yuan, Indonesia's National Research and Innovation Agency, and France's Direction interministérielle du numerique. In Mexico, the Gobierno Municipal de Altamira and Internet para el Bienestar are also claimed as victims.
- Healthcare and education targets: The Fondo Nacional de Salud (FONASA) in Chile, Clinical Associates of the Finger Lakes (CAFL) in the US, and multiple educational institutions in India, Taiwan, Iraq, and Mexico are all listed as alleged victims.
- Telecom and critical infrastructure: Canada's TELUS Communications is alleged to have been breached, alongside a separate claim involving Cisco in the US.
Industry researchers are highlighting a parallel threat in the financial malware space. Reporting on banking trojans notes that Manic, a spyware-equipped threat, is active, while the long-running Grandoreiro campaign continues to target Latin America and Europe. Additionally, an expanded version of ToxicPanda 2.0 is being observed. This activity underscores that while data breaches are a primary concern, direct financial theft via credential-stealing malware remains a persistent and evolving risk for organizations and their customers.
Threat landscape signals
The event distribution shows a notable tilt toward data breach and leak categories (70 combined) versus ransomware (26) and DDoS (34). This suggests that the current dominant criminal strategy is data exfiltration for sale or extortion, rather than purely disruptive attacks. The presence of multiple actors selling "databases" -- including specific country-based datasets for Germany, Mexico, India, and Vietnam -- points to a commoditized market where personal data is a primary currency. The concentration of victims in the US (35), India (24), and Indonesia (14) may reflect both the size of these markets and the perceived ease of compromising organizations with weaker security postures. The activity of actors like Divaccx Gnath and KARAWANG ERROR SYSTEM against Indonesian and Indian targets suggests regional threat clusters are actively harvesting data, likely for both direct fraud and resale.