Today’s Menu (30-second skim)
- Millions of airport customers had contact details exposed: A cyberattack exposed contact and travel-related details for about 8.7 million airport customers, giving scammers more fuel for believable fake alerts.
- A healthcare giant disclosed a cyber incident tied to stolen data: McKesson reported a cyber incident involving stolen data, raising the risk of fake healthcare messages, billing scams, and identity theft.
- Popular browser add-ons were caught stealing data after updates: Researchers found browser extensions that turned malicious after updates and then stole browsing data, account details, and login secrets.
1) Millions of airport customers had contact details exposed

What happened (plain English): Manchester Airports Group said a cyberattack affected about 8.7 million customers. The exposed data was connected to airport Wi-Fi sign-ups and some bookings for parking, lounges, and Fast Track services. The company said the data included contact details such as email addresses, phone numbers, postcodes, and vehicle registration numbers. It also said payment card details were not stored in the affected system. Even so, the airports warned customers to watch for phishing emails and texts that use this information to look real.
Why it matters to you: This kind of data is enough to make scam messages feel personal and urgent. A criminal could send a fake text about airport parking, a refund, or a booking problem and include details that make you trust it. Someone could also pretend to be from the airport and ask you to confirm your account, payment, or one-time code. Even without your card number, this can still lead to account takeovers or stolen money if you are rushed.
How to protect yourself (do this):
- If you get a travel warning or booking problem message, open the airline or airport site yourself instead of tapping the link.
- Be extra suspicious of messages that mention parking, lounge access, Wi-Fi, refunds, or urgent booking changes.
- If a message asks for payment, passwords, or one-time codes, stop and verify through the phone number or app you already use.
Published: 2026-08-27
Source: The Record
2) A healthcare giant disclosed a cyber incident tied to stolen data

What happened (plain English): McKesson said it found a cybersecurity incident involving unauthorized access to third-party applications and data theft. The company said the investigation was still in the early stages, so not every detail is known yet. It also warned that some customers could notice slowdowns in service while the review continues. BleepingComputer reported that the extortion group ShinyHunters claimed responsibility and said the attackers got in through voice-phishing attacks against employees. The same report said the group claimed it stole a huge number of patient-related records, although that count may refer to records rather than unique people.
Why it matters to you: Healthcare data is valuable because it can be used for more than one kind of scam. A criminal might send a fake bill, a fake insurance fix notice, or a fake patient portal email that pressures you to log in or share private details. Someone could also call pretending to help after the breach and ask for your date of birth, insurance number, or verification code. People tend to trust medical messages quickly, which makes this kind of scam especially effective.
How to protect yourself (do this):
- Do not trust surprise calls or emails that claim to be helping with a healthcare breach unless you called back using a known number.
- Check explanation-of-benefits statements, pharmacy messages, and medical bills for anything you do not recognize.
- If a healthcare company says it will contact you, look up the notice on its official website before replying or sharing personal details.
Published: 2026-08-28
Source: BleepingComputer
3) Popular browser add-ons were caught stealing data after updates

What happened (plain English): Researchers found browser extensions for Chrome and Edge that were delivering malware instead of simply doing their stated job. Some of these add-ons were harmless at first, then became dangerous after being sold or updated. One example reportedly had tens of thousands of users before it turned malicious. The bad code could steal browsing data, capture account information, and replace normal pages with fake ones built to trick people. That means a tool you trusted last month could quietly become a problem this month.
Why it matters to you: Browser extensions can see a lot of what you do online, so a bad one can cause real damage without obvious warning signs. A malicious add-on could swap in a fake login page for email, shopping, or banking and trick you into typing your password. It could also target crypto users by asking for wallet phrases or changing what appears on the screen at the worst time. Because updates happen quietly, people often do not realize the risk until after information is stolen.
How to protect yourself (do this):
- Remove browser extensions you do not truly need, especially ones you forgot you installed.
- Before installing an add-on, check who made it, how long it has existed, and whether recent reviews complain about strange behavior.
- If your browser suddenly shows odd pop-ups, changed pages, or asks for wallet phrases or repeated logins, disable extensions first and sign in again only on the real site.
Published: 2026-08-30
Source: BleepingComputer
Grandma’s Firewall

This week’s simple rule: Use the slow path: when a security message, browser add-on, or account warning wants quick action, close it and start again from your own app, bookmark, or phone number.
Two scripts you can steal:
- I do not handle security problems from surprise links or pop-ups. I will open the real site myself.
- I am not installing that add-on or sharing any code right now. I will check it later through the official app or website.
