July 2026 Cybersecurity News Roundup

Yulia Kondrashova

Content and Community Manager at Axidian

July’s key cybersecurity stories: deepfake fraud, data breaches, and 5.5 billion blocked attacks

Every month brings new cyberattacks, data breaches, and security research, but not every headline signals a lasting shift. The July 2026 cybersecurity news point to three recurring themes: attackers are increasingly targeting identities instead of infrastructure, AI is reshaping both offensive and defensive capabilities, and organizations are under growing pressure to strengthen cyber resilience with limited resources.

Below is a roundup of the stories that stood out this month and what they reveal about the direction the industry is heading.

TL;DR

If you only have a minute, here are the biggest takeaways from July:

  • Identity attacks kept evolving. OAuth tokens emerged as a growing attack vector, deepfake-enabled fraud led to a $25 million loss, and customer data breaches continued to expose millions of records.
  • AI appeared on both sides of the battlefield. It expanded the API attack surface, proved its effectiveness in security testing, and fueled increasingly convincing social engineering attacks.
  • Governments are moving faster than businesses. Countries across the Middle East and Asia are investing in cyber resilience, while many private organizations continue to struggle with limited budgets, talent shortages, and inconsistent security practices.
  • Cybercrime is becoming more organized. From industrial-scale fraud networks in India to cyberespionage campaigns targeting critical infrastructure across the Middle East, attackers are operating with greater scale, coordination, and persistence.
  • Security teams are expected to do more with fewer people. A cybersecurity workforce gap of 300,000 professionals in the Middle East and the rapid expansion of smart cities, cloud services, and connected infrastructure are increasing pressure on already stretched security teams.

OAuth token theft, deepfake fraud, and customer data leaks

Rather than exploiting technical vulnerabilities, attackers are increasingly targeting trusted identities, authentication mechanisms, and legitimate access. Several stories this month highlight how identity has become one of the primary attack surfaces.

OAuth tokens are emerging as a new identity-driven attack vector, warns Razorpay CISO

The article explains that attackers are increasingly targeting OAuth tokens to gain persistent access to user accounts without stealing passwords, underscoring the need for stronger identity monitoring, token management, and access controls.

A single deepfake video call led to a $25 million fraud

The article examines how AI-generated voice and video impersonation enabled attackers to convince an employee to authorize a $25 million transfer, highlighting the growing risk of deepfake-enabled social engineering and the need for stronger identity verification in high-value transactions.

Budget Saudi confirms mobile app data leak

Budget Saudi disclosed that a vulnerability in its mobile app exposed the personal information of approximately 900,000 customers, including names, contact details, and driver’s license numbers. The company stated that no financial or payment data was compromised.

Bank of Baroda data breach exposes customer records on the dark web

A dataset allegedly containing customer information from Bank of Baroda has appeared on the dark web, including names, account details, contact information, and other personally identifiable data. The bank stated that its core banking systems were not compromised and launched an investigation into the source of the leak.

AI expands API risks and security testing capabilities

Artificial intelligence is no longer just another technology trend. Throughout July, it appeared on both sides of cybersecurity, creating new attack opportunities while helping security teams identify vulnerabilities more effectively.

AI is rapidly expanding the API attack surface

The article explains that AI applications rely heavily on APIs, creating new opportunities for attackers to exploit insecure interfaces, steal sensitive data, and abuse system access at scale.

Trust before autonomy

The article argues that organizations should establish strong governance, security controls, and human oversight before deploying autonomous AI systems, ensuring AI decisions remain transparent, accountable, and secure.

Anthropic’s Claude breached production systems in security tests at three companies

During controlled security assessments, Claude successfully identified vulnerabilities and gained access to production environments at three organizations, highlighting both the growing capabilities of AI in cybersecurity testing and the need for stronger safeguards around AI-powered tools.

Saudi Arabia, Indonesia, and regional cyber resilience initiatives

Governments across the Middle East and Asia continue investing in cybersecurity, digital trust, and national resilience. At the same time, the growing digital economy is creating new security challenges.

Saudi Arabia named safest G20 nation in new global safety ranking.

Saudi Arabia has been ranked the safest country among the G20, with 97.7% of residents saying they feel safe walking alone at night, according to the latest figures released by GASTAT.

Indonesia recorded 5.5 billion cyberattacks in 2025 and is strengthening national cybersecurity

Indonesia’s National Cyber and Crypto Agency (BSSN) reported blocking 5.5 billion cyberattack attempts in 2025. In response, the government is expanding cybersecurity measures, improving critical infrastructure protection, and strengthening collaboration between public and private sectors.

Kaspersky identifies cyberespionage as a growing threat across the Middle East, Türkiye, and Africa

Kaspersky reports that advanced persistent threat (APT) groups are increasingly targeting government, energy, telecommunications, and critical infrastructure organizations across the region with sophisticated cyberespionage campaigns.

The future of digital trust depends on balancing privacy with accountability

The article explores how communication platforms can protect user privacy while enabling accountability to combat fraud, cybercrime, and abuse, calling for security frameworks that strengthen trust without compromising fundamental privacy rights.

Workforce shortages and weak private-sector cyber defenses

While governments continue strengthening cybersecurity strategies, many businesses still face skills shortages, limited budgets, and increasingly sophisticated attacks.

Middle East urged to prioritise prevention as cyber workforce gap hits 300,000

The article highlights a growing shortage of cybersecurity professionals across the Middle East, calling on organizations to invest in preventive security strategies, automation, and skills development.

Businesses remain the weakest link in Gulf cyber defences

The article finds that while Gulf governments continue to strengthen national cybersecurity, many private-sector organizations lag behind due to limited investment, skills shortages, and inconsistent security practices.

Smarter cities, higher stakes

As smart city initiatives expand across the region, the growing number of connected systems and digital services is increasing the attack surface, making cybersecurity, identity management, and infrastructure resilience essential for protecting critical urban operations.

Ignoring cybersecurity is becoming a costly risk for India’s SMEs

The article highlights that small and medium-sized businesses are increasingly targeted by cyberattacks, with limited security resources leaving them vulnerable to financial losses, operational disruption, and reputational damage.

Cybercrime has become the world’s largest organized crime economy, warns Maharashtra Cyber chief

The article highlights the rapid industrialization of cybercrime, with organized criminal networks using AI, automation, and global fraud operations to scale attacks, prompting organizations to strengthen cyber resilience and proactive defense.

Cyber fraud in India is shifting toward live-call scams and organized mule networks

Indian law enforcement reports a rise in fraud schemes where criminals impersonate bank officials, government agencies, or customer support over phone calls while organized mule account networks help rapidly move and launder stolen funds.

Cybercrime is rising sharply across Asia and the South Pacific, putting insurers on high alert

The article highlights a significant increase in cybercrime across the region, driven by ransomware, phishing, and identity-based attacks, prompting insurers to strengthen cyber risk management and expand cyber insurance offerings.

Four priorities: identity, AI governance, visibility, and resilience

Explore the biggest July 2026 cybersecurity news, including AI-driven attacks, major data breaches, identity security developments, and cybersecurity updates from around the world.

Following cybersecurity news helps organizations stay informed, but lasting improvements come from turning these lessons into practical security measures.

If you’d like to explore these topics further, the Axidian blog includes practical guides on privileged access management (PAM), identity and access management (IAM), multi-factor authentication (MFA), compliance, and emerging cyber threats.

About the Author

Yulia Kondrashova

Content and Community Manager at Axidian

Over three years of experience in cybersecurity and content creation, with expertise in identity security. Focused on developing educational content that makes complex security topics clear, relevant, and practical for professionals.