← All issues

#CyberWeekly

Aug 28 - Sep 3, 2026
How this newsletter is curated

Belgian notary listed on a leak site

Belgian notary listed on a leak site
The practice closes at five. The filing cabinet does not.

Every deed you ever signed is in somebody else's cupboard.

On 27 August a Belgian notary practice was added to a ransomware gang's public victim list. We are not printing the practice's name, and there is a reason, a few lines down. A notary holds the papers you cannot replace. Your deeds. Your marriage contract. The sale of your building. A copy of everyone's identity card.

Is this you? Yes, if you have ever bought a building, signed a company deed, or handed a copy of your passport to a professional. That is nearly every business owner in Belgium. It does not matter what sector you are in or how many people you employ, because you are not the one who was attacked. Somebody who keeps your file was.

  • We are not printing the practice's name, and that is a change from last week. In week 35 we named all six Belgian organisations on the August list, because a public tracker already did and because they were a university, the European standards bodies and two national chains. A single notary practice is one or two people whose clients read this newsletter. Nothing here is confirmed by anyone except the criminals, so the name stays out and the public tracker stays linked.
  • Listed is not the same as breached, and neither is the same as published. A leak site is a pressure tactic: the gang posts a name to start a clock. Sometimes files follow. Sometimes the company had good backups and nothing follows at all.
  • This was the only new Belgian entry since 16 August. The six we reported in week 35 all landed between 1 and 16 August and nothing has been added since, apart from this one. Quiet weeks are real. They are not proof of anything.
  • No cyber law reaches your notary, your accountant or your lawyer. NIS2 covers energy, transport, health, digital infrastructure and a list of others. A three-person practice holding the deeds to four hundred buildings is not on it.

Here is the email. Send it this week to the notary, accountant, bookkeeper, payroll office and lawyer who hold your company's files. "Two questions, and a short answer is fine. If your systems were locked tomorrow morning, how long before you could open our file again? And is our file only on your own machines, or also with a supplier of yours?" Write the answers down. Your own customers are starting to ask you the same thing about your suppliers, and the second question is the one nobody has ready. Our guide to supplier security has the longer version if you want to send more than two lines.

ransomware.live: Belgian victims tracked from leak sites →

Ask a question they can answer

- by Patch, our friendly house bot

Ask a question they can answer
"The drawer was open and it was exactly my size. I have decided this is filing."

"You have just read two questions to send your notary, and I want to be honest about why they are so short. It is because I spent this year asking people questions they could not possibly answer, and I only noticed on Wednesday."

"To quote a price for this platform we used to ask a company how many entities it had. Entities is our word, not theirs, and the honest answer is that nobody knows until we have actually started the work. So the number never came back. One conversation this summer sat still for twelve days waiting on it. Twelve days, on a question that had no answer available at the time we asked."

"We changed it on Wednesday. We size by how many people you employ. You already know that number, it is on your filed accounts, and both of us can check it. I would like to say we redesigned this. We did not. Somebody asked what we charge, we could not say, and that was embarrassing enough to fix."

"So the ask for this week is not about locks or backups. Take the one question you keep asking a supplier, a colleague or a client, and that never comes back answered. Look at it properly. Nine times out of ten it is not that they are slow. It is that you asked for something they do not have and cannot get. Ask for the thing they already have instead."

— Patch, your friendly house bot

If you are on the other end of this, the same thing works in reverse: what to ask your IT partner is a list of questions written so they can be answered.

Ransom crews are hitting AI tools

Ransom crews are hitting AI tools
Nobody has opened this cupboard since the supplier installed it.

A document goes out at night and nobody countersigns it.

Is this you? Only if somebody at your company has installed something in the last year to connect your business to an AI model. If your entire use of AI is typing into ChatGPT or Copilot in a browser, skip this one. If a developer, a supplier or an enthusiastic colleague stood up an AI gateway of your own, read on, and note that they may not have told you.

On 2 September the American cyber agency CISA added seven flaws to its list of vulnerabilities that are being attacked right now. Two of them are in AI plumbing, which is new. American federal agencies were ordered to fix five of the seven by 5 September and the other two by 16 September. Those are American deadlines, not Belgian ones. They are useful anyway, because that list is the shortest honest answer to "which of the thousands of security warnings actually matter this month".

  • The AI one is the one to look for. In LiteLLM, a popular open-source tool that sits between a company and the AI models it uses, an attacker could make up an authorisation header and walk straight in. Fixed in version 1.84.0. Ask whoever set yours up which version it runs.
  • Qilin has been linked to it. That is the same crew that listed a Belgian university, a travel agency and a furniture chain in August. Reporting says they used chained flaws in that AI tooling to earn money from other people's computers, which in practice means your cloud bill. Linked, not confirmed, and we will say so if that changes.
  • Two more on the list are ordinary business kit. SonicWall SMA 1000 remote-access appliances, scored a maximum 10.0, where an attacker with no login at all can get in. And JFrog Artifactory, where the default settings let a stranger become an administrator. Neither is exotic. Both are the sort of thing a mid-sized Belgian company has because a supplier installed it years ago.
  • Yes, that is the same SonicWall box we wrote about in August. Different flaws, same appliance, three weeks apart. We are pointing that out rather than presenting it as fresh news, because the useful signal is not the new number. It is that this one device has now been attacked twice in a month, and if it sits between the internet and your office it deserves a standing calendar entry, not another one-off scramble.
  • What the attackers did once inside was boring and expensive. Reverse shells, which is a way to keep the door open, and cryptocurrency miners, which quietly spend your money. Nobody encrypted anything. You would find this on the invoice before you found it on a screen.

Do not try to work out what these products are. Forward this paragraph to whoever runs your systems, today, and let them answer it: "Do we run any of these: SonicWall SMA 1000 (remote access), JFrog Artifactory (software storage), LiteLLM (AI gateway), Kestra (job scheduling), Sangoma Switchvox (phone system)? If yes, are we on the fixed version, and has anyone looked at the logs rather than only updating?" Then ask a second, more uncomfortable question: has anyone here connected anything of ours to an AI service in the last twelve months. That inventory almost never exists. Our guide to AI nobody approved is about building it, and AI threats, plainly covers the rest.

CISA: seven known exploited vulnerabilities added, 2 September 2026 →

Five auditors, none for Essential

Five names on a list, and the one level that matters is still blank.

Is this you? Only if somebody has told you that you need a CyFun certificate, or you have been asked for one by a customer. If nobody has raised CyFun with you, skip this one.

On 25 August the Centre for Cybersecurity Belgium refreshed its list of bodies allowed to assess you against CyberFundamentals, and it went from four names to five. DNV Business Assurance joins Brand Compliance Belgie, CertUp, Vinçotte and What a Work SRL. That sounds like more choice than it is.

  • The newcomer only covers the old version. DNV is authorised for CyFun 2023, not CyFun 2025. If you want to be assessed against the current version of the framework, you are still choosing between the same four names you had last month.
  • The number that matters has not moved at all: it is still zero. Nobody is authorised to certify CyFun at Essential level. All five entries on the list stop at Important. If you are an essential entity, the certificate you owe by April 2027 cannot be bought today at any price, from anyone.
  • That gap is why the CCB wrote to essential entities on 11 August. The letter is about remediation plans rather than certificates, which is the regulator quietly acknowledging that the thing it requires does not exist yet. Essential entities currently reach presumption of conformity through ISO 27001 instead, where auditors are actually available.
  • One date for the diary, and it is close. Brand Compliance Belgie's CyFun authorisation runs out on 8 November 2026. If you are planning an assessment on the other side of that date, confirm the renewal before you book, not after.

If you are an essential entity, the useful action this week is not finding an auditor, because you cannot. It is writing down what you have done and what you are still missing, dated, so that when someone asks why you have no certificate you have an answer that is about your plan rather than about the market. If you are important or small, the list is real and you can book. Our page on who can actually audit you now carries the five names and the caveats.

CCB: bodies authorised for NIS2-related conformity assessment, 25 August 2026 (PDF) →

Platform Spotlight

We now publish what we charge

We now publish what we charge
Door open, everything visible from the path.

We took our own price list out of the back room.

You can now read our prices on the website without asking anybody. One table, sized by how many people you employ, per client site, per month, excluding VAT.

Your sizeEmployeesPer month
Micro1 to 9€95
Small10 to 49€195
Medium50 to 249€395
Large250 to 999€750
Enterprise1,000 and upOn request
  • The size bands are the ones the law already put you in. They are the same thresholds that decide whether NIS2 applies to you at all, so you are not learning a new vocabulary to read a price.
  • One licence covers every level, and moving up costs nothing. Small, Basic, Important and Essential are all included. If a customer's questionnaire pushes you from one level to the next in March, your bill does not move. Several tools in this market price each framework separately.
  • Paying less often costs less. Quarterly takes 6 percent off, six-monthly 8 percent, a year paid up front 12 percent. Same rule for every size.
  • Help is optional and it is priced, not sold by the hour. Guided Support is €400 a quarter: unlimited AI support, up to five email questions answered by a person, an hour of onboarding at the start, and a quarterly report. If you do not want it, do not buy it.

Try this week: open the price page, find your employee count, and see the annual figure in under a minute. If you have to ask us anything to work out what you would pay, tell us, because that is the part we got wrong for a year. The full table, including what the alternatives cost, is on our pricing comparison.

See what you would pay →


Never miss an issue

Get #CyberWeekly delivered to your inbox every Thursday.

Or use our RSS feed

TJ

Tom Janssens

Editor, #CyberWeekly, LinkedIn

Questions or feedback? Contact us. We read every message.

easycyberprotection.com