Quick answer: For the week of July 12, 2023, the standout story is the alleged ransomware attack on Barts Health NHS (National Health Service) Trust, where the ALPHV ransomware gang claims to have stolen 70 terabytes of patient data. Healthcare and public-sector organizations should audit third-party access to clinical systems and confirm offline, tested backups now.
This week’s stories:
- Barts Health NHS Trust ransomware claim: ALPHV gang alleges theft of 70 terabytes of UK healthcare data.
- Microsoft completes the Azure AD to Microsoft Entra ID rebrand and previews two new secure access services.
- Chinese state-linked group Storm-0558 breached US and Western European government email accounts via a Microsoft Cloud exploit.
- The Cl0p MOVEit breach reaches Deutsche Bank, ING, Postbank, and Comdirect through shared vendor Majorel.
- Attackers forge kernel-mode driver signatures by abusing a Windows code-signing policy loophole, per Cisco Talos.
Published: July 2023. Updated: August 2026 (formatting, structure, and analysis refreshed; the news items below are an accurate historical record and have not been altered). Reviewed by Encryption Consulting’s Threat Intelligence team.
About this series
This edition is part of Encryption Consulting’s ongoing Data Privacy Weekly series, a recurring roundup of notable data protection and cybersecurity news. Read the previous edition (July 1, 2023) or continue to the next edition (July 27, 2023).
Methodology: Each edition is compiled by Encryption Consulting’s research team from established, independently reported cybersecurity and data privacy news outlets published during that calendar week. Stories are selected for relevance to enterprise security, identity, encryption, and compliance audiences, then summarized with a cited primary source and dated for easy reference.
01. UK National Health Service Faces Largest-Ever Ransomware Attack
UK battles a rising wave of cyberattacks as Barts Health NHS Trust investigates alleged ransomware incident. ALPHV ransomware gang claims to have stolen 70 terabytes of sensitive data, including passports and confidential emails, in what they say is the biggest breach of healthcare data in the UK.
This follows a recent ransomware attack on the University of Manchester, where hackers accessed an NHS dataset with information on 1.1 million patients. The UK’s public sector, including Ofcom and the University of the West of Scotland, has been targeted by cyberattacks in recent months.
Enterprise implication: Healthcare and public-sector networks that share patient records with third parties or academic partners create a single high-value target; one compromised vendor or research dataset can expose millions of records at once.
Recommended action: Audit which third parties and research partners hold copies of patient or citizen data, and confirm immutable, offline backups are tested and restorable.


02. Microsoft rebrands Azure Active Directory to Microsoft Entra ID
Microsoft is rebranding its Azure Active Directory (Azure AD) as Microsoft Entra ID. The name change, set to be completed by the end of 2023, will not affect the service’s capabilities, including single sign-on and multifactor authentication. Microsoft also introduced two new services, Entra Internet Access and Entra Private Access, in public preview.
Entra Internet Access secures public-facing web services, while Entra Private Access allows remote access to internal corporate resources. The company aims to expand Microsoft Entra to enhance security and provide real-time access decisions.
Enterprise implication: A name change alone does not reduce identity risk; organizations that have not centralized single sign-on (SSO) and multi-factor authentication (MFA) policies in Azure AD/Entra ID remain exposed regardless of the rebrand.
Recommended action: Use the rebrand as a trigger to review Entra ID conditional access policies, enforce MFA for all admin accounts, and pilot Entra Internet Access and Entra Private Access before retiring legacy VPN access.
03. Chinese Hackers Breach US Government Emails in Microsoft Cloud Exploit
Chinese hackers breached US government emails through a Microsoft Cloud exploit, gaining unauthorized access to email accounts for a month before being detected. The breach, carried out by a China-based hacking group referred to as “Storm-0558,” targeted email systems for intelligence collection and impacted around 25 organizations, including government agencies in Western Europe and the US. Microsoft has implemented mitigations and is working with authorities to protect affected users, while the exact number of compromised organizations and government agencies remains undisclosed.
Enterprise implication: A month-long undetected breach of cloud email accounts shows that token and key validation weaknesses inside a cloud provider can bypass an organization’s own controls entirely, including for government and Fortune 500 tenants.
Recommended action: Review cloud email sign-in and token issuance logs for anomalies, rotate and tightly scope any long-lived API or signing keys tied to Microsoft cloud services, and confirm Microsoft’s published mitigations have been applied to your tenant.
04. MOVEit Cyber Attack Affects Deutsche Bank, ING, Postbank, and Comdirect
Deutsche Bank, ING, Postbank, and Comdirect have experienced customer data leaks due to a breach in the Cl0p MOVEit hacks. The banks used the same third-party vendor, Majorel, which suffered a cyber-attack. The leaked information includes customers’ names and international banking account numbers, potentially enabling unauthorized direct debits.
Only customers who used the account switching service during specific periods are affected. ING Bank and Comdirect have also confirmed their involvement in the breach. The banks recommend that customers monitor their accounts for unauthorized transactions. The MOVEit attacks have impacted numerous companies globally.
Enterprise implication: Cl0p, the ransomware and data-extortion group behind the MOVEit campaign, reached four banks through a single shared vendor, Majorel, showing how one unpatched third-party file-transfer tool can cascade customer data exposure across an entire supply chain. See Encryption Consulting’s roundup of major supply chain attacks for related incidents.
Recommended action: Inventory every third-party vendor with access to customer PII, including subcontractors like Majorel, and require evidence that MOVEit and other managed file-transfer software has been patched.
05. Hackers Exploit Windows Policy Loophole, Forge Kernel-Mode Driver Signatures
Hackers are exploiting a Windows policy loophole to forge signatures on kernel-mode drivers, primarily targeting Chinese-speaking threat actors. Cisco Talos reported that the attackers are using open-source tools to alter driver signing dates and load malicious drivers with expired certificates. Microsoft has taken steps to block all certificates and stated that no compromise of Microsoft accounts has been identified.
The weakness stems from an exception allowing cross-signed drivers under specific conditions. Threat actors use signature timestamp forging software to deploy thousands of unsigned drivers, bypassing Microsoft’s verification process. This method poses a significant threat, granting full access and compromising the system.
Enterprise implication: Forged driver signatures let malicious code load at the kernel level with full system privileges, undermining code signing as a trust anchor for security software and operating system components alike.
Recommended action: Inventory code-signing certificate exposure across your driver and software release pipeline, and follow Encryption Consulting’s code signing best practices to harden signing key custody and timestamp validation.
This Week at a Glance
| Story | Category | Real-World Impact |
|---|---|---|
| Barts Health NHS Trust ransomware claim | Healthcare / Ransomware | Alleged theft of 70 terabytes of UK patient data, including passports and internal emails |
| Azure AD renamed Microsoft Entra ID | Identity and Access Management | No functional change to SSO/MFA; two new secure access services enter public preview |
| Storm-0558 Microsoft Cloud email breach | Nation-State / Cloud Security | Undetected, month-long access to government email accounts across roughly 25 organizations |
| MOVEit/Cl0p breach via vendor Majorel | Third-Party / Vendor Risk | Customer names and banking account numbers exposed at four major European banks |
| Windows driver-signature forgery | Code Signing / Malware | Kernel-level driver loading via forged signatures, primarily against Chinese-speaking targets |
Limitations
- This roundup is a curated selection of publicly reported stories from the week of July 10 to 12, 2023, not an exhaustive record of every data privacy or security event during that period.
- All facts, quotes, and figures are sourced from the third-party outlets cited below (TechCrunch, BleepingComputer, The Verge, Cybernews, The Hacker News) and reflect reporting available at the time of original publication in July 2023.
- Some details, such as the full number of organizations affected by the Storm-0558 breach, were undisclosed at the time of reporting and may have since been clarified by the original sources.
- This series reflects Encryption Consulting’s editorial judgment about which stories carry the most relevance for security, privacy, and compliance teams, and is not a substitute for direct monitoring of vendor advisories or regulatory notices affecting your organization.
Frequently Asked Questions
What happened in the Barts Health NHS Trust ransomware incident?
The ALPHV ransomware gang claimed to have breached Barts Health NHS Trust in the UK, alleging theft of 70 terabytes of data including passports and confidential emails. The trust was investigating the claim as of mid-July 2023. It followed a separate ransomware attack on the University of Manchester that had already exposed an NHS dataset covering 1.1 million patients.
Did Microsoft’s Entra ID rebrand change how Azure AD security works?
No. Microsoft renamed Azure Active Directory to Microsoft Entra ID, but core capabilities such as single sign-on (SSO) and multi-factor authentication (MFA) were unchanged. Alongside the rebrand, Microsoft introduced two new services in public preview, Entra Internet Access and Entra Private Access, aimed at securing internet-facing and internal corporate resources respectively.
Who was affected by the Storm-0558 Microsoft Cloud breach?
A China-based group tracked as Storm-0558 accessed email accounts belonging to roughly 25 organizations, including US and Western European government agencies, over about one month before detection. Microsoft has since implemented mitigations, though the full list of affected organizations has not been publicly disclosed.
How did the MOVEit/Cl0p breach reach Deutsche Bank and other banks?
Deutsche Bank, ING, Postbank, and Comdirect were affected indirectly through Majorel, a shared third-party vendor compromised in the broader Cl0p MOVEit campaign. Exposed data included customer names and international banking account numbers for customers who had used an account-switching service during specific periods, not full banking credentials.
More from Data Privacy Weekly
Continue reading the series: Data Privacy Weekly, July 1, 2023 (previous edition) and Data Privacy Weekly, July 27, 2023 (next edition).
References
- TechCrunch: UK hacks, public sector, NHS ransomware
- BleepingComputer: Microsoft rebrands Azure Active Directory to Microsoft Entra ID
- The Verge: Security breach, China, US government emails, Microsoft Cloud exploit
- Cybernews: Deutsche Bank, ING, Postbank impacted by MOVEit hack, Cl0p
- The Hacker News: Hackers exploit Windows policy loophole
