---
title: "Russia's NoName Hacks Quebec Water Plant | Util… | Firevault"
description: "Russia-linked NoName breached a Quebec water treatment plant's SCADA. What UK and Canadian water utilities must isolate, air-gap and audit now."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/russian-noname-hack-quebec-water-treatment-plant#webpage",
      "url": "https://fire-vault.com/news/russian-noname-hack-quebec-water-treatment-plant",
      "name": "Russia's NoName Hacks Quebec Water Plant",
      "description": "Russia-linked NoName breached a Quebec water treatment plant's SCADA. What UK and Canadian water utilities must isolate, air-gap and audit now.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/7ee07055-807f-48ab-aa25-1607f065f99e/quebec-water-plant-hero.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/russian-noname-hack-quebec-water-treatment-plant#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/russian-noname-hack-quebec-water-treatment-plant#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Russia's NoName Hacks Quebec Water Plant | Utility Response",
          "item": "https://fire-vault.com/news/russian-noname-hack-quebec-water-treatment-plant"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Russia's NoName Hacks Quebec Water Plant | Utility Response",
      "description": "Russia-linked NoName breached a Quebec water treatment plant's SCADA. What UK and Canadian water utilities must isolate, air-gap and audit now.",
      "url": "https://fire-vault.com/news/russian-noname-hack-quebec-water-treatment-plant",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/7ee07055-807f-48ab-aa25-1607f065f99e/quebec-water-plant-hero.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/7ee07055-807f-48ab-aa25-1607f065f99e/quebec-water-plant-hero.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/7ee07055-807f-48ab-aa25-1607f065f99e/quebec-water-plant-hero.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/7ee07055-807f-48ab-aa25-1607f065f99e/quebec-water-plant-hero.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-07-05T09:49:53.233554+00:00",
      "dateModified": "2026-07-20T15:39:10.616721+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/russian-noname-hack-quebec-water-treatment-plant"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breaking",
      "wordCount": 1192,
      "keywords": "Russia's, Breaking, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "Canada''s Communications Security Establishment (CSE) has confirmed in its 2025 to 2026 annual report that Russian hacktivist group NoName broke into the network of a Quebec municipality''s water treatment plant and gained access to systems that control public health. According to CSE, NoName claimed the \"ability to covertly control pumps, chlorine dosing, pressure settings and monitoring and aler",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What did the NoName group actually gain access to in Quebec?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "According to Canada's Communications Security Establishment, the Russian-backed hacktivist group NoName claimed the ability to covertly control pumps, chlorine dosing, pressure settings and monitoring and alerting systems at a Quebec municipal water treatment plant. The intrusion was flagged by the Organization of American States cyber network in October before physical harm was reported."
          }
        },
        {
          "@type": "Question",
          "name": "Could this happen to a UK or European water utility?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. The structural weaknesses NoName exploited, convergence between corporate IT and operational technology, persistent vendor access and long-lived outstations, exist in nearly every water estate in the United Kingdom and Europe. NIS2 and Drinking Water Inspectorate expectations now put boards personally on the hook for preventing exactly this pattern."
          }
        },
        {
          "@type": "Question",
          "name": "What is a physically enforced boundary and why does it matter for dosing systems?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "A physically enforced boundary is a hardware control that prevents any network path from existing between two zones unless a named human explicitly opens it for a defined window. It matters for dosing because a stolen credential or misconfigured firewall rule cannot bypass hardware. Firevault Control applies this pattern between corporate IT, the industrial DMZ, treatment SCADA and outstation telemetry."
          }
        },
        {
          "@type": "Question",
          "name": "Where can water sector leaders get a practical blueprint?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The Firebreak Water Playbook sets out the zone architecture, multi-party authorisation model and regulatory evidence pack for treatment, distribution and outstation telemetry. It is written for water CISOs, engineering directors and boards. You can read it at /playbook/firebreak-water."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Breaking News Updated as information becomes available 

Overview

What CSE actually disclosedWhy this matters for every water…The physical safety consequenceWhat software-layer defences can…The Control answer for waterRegulatory context, UK and EuropeWhat to do this weekShareMore Resources

[Knowledge Vault](/learn/knowledge)/ Breaking 

Breaking · 5 July 2026 · Breaking 

# Russia's NoName Hacks Quebec Water Plant | Utility Response

Russia-linked NoName breached a Quebec water treatment plant's SCADA. What UK and Canadian water utilities must isolate, air-gap and audit now.

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

Mark Fermor Director & Co-Founder, Firevault 

6 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Frussian-noname-hack-quebec-water-treatment-plant)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Frussian-noname-hack-quebec-water-treatment-plant&text=Russia's%20NoName%20Hacks%20Quebec%20Water%20Plant%20%7C%20Utility%20Response%0A%0ARussia-linked%20NoName%20breached%20a%20Quebec%20water%20treatment%20plant's%20SCADA.%20What%20UK%20and%20Canadian%20water%20utilities%20must%20isolate%2C%20air-gap%20and%20audit%20now.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Frussian-noname-hack-quebec-water-treatment-plant)[](mailto:?subject=Russia's%20NoName%20Hacks%20Quebec%20Water%20Plant%20%7C%20Utility%20Response&body=Russia-linked%20NoName%20breached%20a%20Quebec%20water%20treatment%20plant's%20SCADA.%20What%20UK%20and%20Canadian%20water%20utilities%20must%20isolate%2C%20air-gap%20and%20audit%20now.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Frussian-noname-hack-quebec-water-treatment-plant)

![A silhouetted figure with a laptop overlooks a water treatment plant at dusk, with glowing network lines and warning lights overlaying the scene to symbolise a cyber-attack on critical infrastructure.](/__l5e/assets-v1/7ee07055-807f-48ab-aa25-1607f065f99e/quebec-water-plant-hero.jpg)

Breaking 

Article record

**Breaking**Category 

**5 July 2026**Published 

**6 min read**Reading time 

**Mark Fermor**Written by 

A silhouetted figure with a laptop overlooks a water treatment plant at dusk, with glowing network lines and warning lights overlaying the scene to symbolise a cyber-attack on critical infrastructure.

Why it matters

## What this means for organisations holding critical data

Russia-linked NoName breached a Quebec water treatment plant's SCADA. What UK and Canadian water utilities must isolate, air-gap and audit now.

In this analysis

1.  01 [What CSE actually disclosed](#section-0)
2.  02 [Why this matters for every water…](#section-1)
3.  03 [The physical safety consequence](#section-2)
4.  04 [What software-layer defences can…](#section-3)
5.  05 [The Control answer for water](#section-4)
6.  06 [Regulatory context, UK and Europe](#section-5)

**On this page**[What CSE actually disclosed](#section-0)[Why this matters for every water…](#section-1)[The physical safety consequence](#section-2)[What software-layer defences can…](#section-3)[The Control answer for water](#section-4)[Regulatory context, UK and Europe](#section-5)[What to do this week](#section-6)

Canada''s **Communications Security Establishment (CSE)** has confirmed in its 2025 to 2026 annual report that Russian hacktivist group **NoName** broke into the network of a Quebec municipality''s water treatment plant and gained access to systems that control public health. According to CSE, NoName claimed the "ability to covertly control pumps, chlorine dosing, pressure settings and monitoring and alerts systems". The intrusion was flagged by the Organization of American States cyber network in October, not by CSE itself, and the affected municipality has not been named.

This is one of the most specific public confirmations to date that state-aligned actors are inside water infrastructure on the North American side of the Atlantic. It should also settle a question that water sector boards in the United Kingdom and Europe have been quietly debating for two years: whether physical isolation of treatment control systems is proportionate. It is.

## What CSE actually disclosed

The key facts from the CSE report and adjacent reporting by National Post are these:

-   The intrusion targeted a Quebec municipal water treatment plant.
-   NoName claimed access to pumps, chlorine dosing, pressure setpoints and the monitoring and alerting systems that would normally warn operators something was wrong.
-   Detection came through the Organization of American States cyber coordination network, not through the operator''s own monitoring or CSE.
-   The US Department of Justice classifies NoName as a cybercriminal group financially backed by the Russian government and notes that the group frequently targets North American water systems.
-   CSE recorded more than 3,200 cyber incidents affecting Canadian federal organisations or [critical infrastructure](/control-for-critical-infrastructure) sectors in the year covered.

The phrase that matters is "covertly control". Attackers were not simply on the office network. They had reached the layer where a wrong number becomes a public health incident.

> When attackers can nudge a chlorine setpoint and quiet the alarm at the same time, the argument about the cost of physical separation ends. You are now scoring risk in milligrams per litre, not tickets per quarter.

## Why this matters for every water utility

Water companies everywhere run a small central control room connected to a very large field. Thousands of outstations, RTUs and PLCs are reachable over private telemetry. Treatment SCADA sits behind an industrial DMZ, but the corporate estate, the works information management system, asset management and billing frequently share the same paths.

Three structural weaknesses show up in almost every water estate we assess:

-   **IT and OT convergence.** A foothold on the corporate network can be pivoted, through a shared engineering jump server, into a treatment SCADA fabric that was assumed to be separate.
-   **Long-lived outstations.** Kit deployed over decades cannot all be patched at once, and the private APN telemetry that connects it was designed for availability, not adversary resistance.
-   **Persistent vendor and integrator access.** Remote support paths that were opened for a specific project remain in place years later, often outside change control.

Every one of these is a candidate route to the same outcome as Quebec: silent access to dosing, pressure and alerting.

## The physical safety consequence

The reason this incident is different from a [data breach](/learn/breaches) is that a wrong chlorine dose or a spoofed pressure reading is not a compliance finding. It is a public health event and, at scale, a supply event. In the United Kingdom, the Drinking Water Inspectorate holds water companies responsible for wholesomeness at the tap; the NIS2 Directive across the European Union places directors personally on the hook for security of essential services; the US Environmental Protection Agency has issued repeated guidance on the same theme. None of these frameworks accept "a firewall rule was misconfigured" as a defence.

## What software-layer defences cannot do here

Modern water operators already invest in endpoint detection, network monitoring, identity governance and 24/7 SOC coverage. All of it matters. None of it, on its own, prevents the Quebec pattern, because the pattern depends on paths that should not exist being reachable at all.

-   Credential-based controls fail the moment a legitimate vendor account is abused.
-   Firewall rules degrade over time and are rarely reviewed against a written zone model.
-   Historians, engineering workstations and recovery archives are often in the same domain, so an attacker who reaches one reaches the evidence of what they did.

The only control that survives a determined adversary with valid credentials is a physical boundary they cannot cross remotely.

## The Control answer for water

Control is designed for exactly the topology that Quebec exposed. It operates at the network connectivity layer beneath your SCADA and does not require changes to PLC programs, dosing logic or telemetry protocols. It puts a real, physical boundary between the office, the industrial DMZ, the treatment SCADA fabric and the outstation telemetry network, and it enforces named human authorisation for anything that crosses those boundaries.

The four modules apply to water as follows:

-   **Firebreak.** Emergency severance. A compromised zone is physically disconnected during a live incident so an office or telemetry compromise cannot reach the plants.
-   **Isolate.** Enforced physical boundaries between corporate IT, the industrial DMZ, treatment SCADA and outstation telemetry. The paths NoName used in Quebec simply do not exist between zones.
-   **Execute.** Setpoint changes, firmware updates and dosing actions that cross a zone boundary require explicit, named, multi-party approval. A stolen credential is not enough.
-   **Archive.** Verified baselines of treatment recipes, dosing limits and network configuration are held on infrastructure with no live network path to production, so a known-good restore is guaranteed.

Water Sector Playbook

The Firebreak Water Playbook is the sector companion to this incident.

It maps the zone architecture, the multi-party authorisation model and the regulatory evidence pack for treatment, distribution and outstation telemetry. Written for water CISOs, engineering directors and boards.

[Download the Firebreak Water Playbook →](/playbook/firebreak-water)

## Regulatory context, UK and Europe

The Quebec disclosure lands squarely in the middle of an active regulatory push. Under NIS2, water companies operating in the European Union are essential entities with personal liability for directors. In the United Kingdom, the Drinking Water Inspectorate and Ofwat have both signalled tougher expectations on cyber resilience of operational technology. The EPA in the United States has repeatedly warned that treatment SCADA is being probed by state-aligned actors. This is now the reference case regulators will point to when they ask a board a very simple question: could this have happened here, and how would you know?

## What to do this week

1.  **Map every path between corporate IT, WIMS, treatment SCADA and outstation telemetry.** Do not trust the network diagram. Trust a fresh walk of the actual routes, including vendor and integrator jump servers.
2.  **Identify every persistent remote access path.** Anything that is on by default and does not require named, time-bounded authorisation is a candidate for the Quebec pattern.
3.  **Commission a physically enforced zone design.** Aligned to your plants and distribution estate, with a Control module at each boundary and verified configuration baselines held out-of-band.

Sector Blueprint

See the full Water Control blueprint.

Treatment SCADA, outstation telemetry, dosing safety and regulatory evidence, mapped module by module.

[Control for Water Utilities →](/solutions/control/utilities/water) [Download the Firebreak Water Playbook →](/playbook/firebreak-water)

_Sources: [National Post via Yahoo News Canada](https://ca.news.yahoo.com/russian-group-hacked-quebec-water-080005964.html); [CSE Annual Report 2025-2026](https://www.cse-cst.gc.ca/en/accountability/transparency/reports/communications-security-establishment-canada-annual-report-2025-2026); [US Department of Justice on NoName](https://www.justice.gov/opa/pr/justice-department-announces-actions-combat-two-russian-state-sponsored-cyber-criminal)._

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://ca.news.yahoo.com/russian-group-hacked-quebec-water-080005964.html)

About the author

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your data sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Command**Access windows and retrieval under your control 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![FBI FLASH: TeamPCP Hits Software Supply Chain, Steals Cloud Keys](/__l5e/assets-v1/d0b7d825-a497-405f-943d-e15e09a5406d/teampcp-fbi-flash.jpg)

Breaking 

### FBI FLASH: TeamPCP Hits Software Supply Chain, Steals Cloud Keys

FBI FLASH warns that TeamPCP is compromising widely used developer and security tools to steal cloud tokens, SSH keys and Kubernetes secrets. What UK organisations must isolate now.

5 Jul 2026 4 min 







](/news/fbi-flash-teampcp-software-supply-chain-attacks)[

![Iran-linked hackers shut down a UK power plant for four days](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/iran-uk-power-plant-cyber-attack-2026.jpg)

Insight 

### Iran-linked hackers shut down a UK power plant for four days

A small British generator was taken offline for four days after an Iran-linked cyber attack, reported as the first successful intrusion of its kind against UK power generation. The grid held. The control layer did not.

23 Aug 2026 4 min 







](/news/iran-linked-hackers-uk-power-plant-shutdown-2026)[

![GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/gta6-leaks-rockstar-2026.jpg)

Insight 

### GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?

Unreleased Grand Theft Auto 6 footage has appeared online ahead of Rockstar's official preview, and Take-Two is now in court seeking the identities behind the accounts sharing it. The game will still sell. The material that leaked can never be unseen.

22 Aug 2026 3 min 







](/news/gta-6-leaks-rockstar-development-footage-2026)[

![Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/nine-pbs-archives-cloud-vendor-shutdown-2026.jpg)

Insight 

### Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed

A public broadcaster lost access to fifty terabytes of archival footage, spanning seventy years of regional history, when its cloud storage supplier suddenly went out of business. The files are still trapped in a Denver data centre.

18 Aug 2026 4 min 







](/news/nine-pbs-archives-cloud-vendor-shutdown-2026)[

![When Access Fails: Continuity Needs Offline Secure Storage](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/when-the-grid-fails-offline-secure-storage-business-continuity-2026.jpg)

Industry Insight 

### When Access Fails: Continuity Needs Offline Secure Storage

Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline, whatever the cause.

18 Aug 2026 9 min 







](/news/when-the-grid-fails-offline-secure-storage-business-continuity)[

![French tax authority breach exposes 678,000 taxpayers and the land registry behind them](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/french-tax-authority-dgfip-data-breach-2026.jpg)

Insight 

### French tax authority breach exposes 678,000 taxpayers and the land registry behind them

France's Directorate General of Public Finances has confirmed that attackers used compromised access points to extract tax and cadastral data on 678,000 individuals and businesses. The same seller claims to have held a live session on the central land registry platform covering roughly 20 million people.

17 Aug 2026 3 min 







](/news/french-tax-authority-dgfip-data-breach-678000-2026)

Share this article

Breaking News 

Breaking 5 July 2026 6 min read 

## Russia's NoName Hacks Quebec Water Plant | Utility Response

Russia-linked NoName breached a Quebec water treatment plant's SCADA. What UK and Canadian water utilities must isolate, air-gap and audit now.

![Russia's NoName Hacks Quebec Water Plant | Utility Response](/__l5e/assets-v1/7ee07055-807f-48ab-aa25-1607f065f99e/quebec-water-plant-hero.jpg)

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

Published by Mark Fermor , Director & Co-Founder 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Frussian-noname-hack-quebec-water-treatment-plant)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Frussian-noname-hack-quebec-water-treatment-plant&text=Russia's%20NoName%20Hacks%20Quebec%20Water%20Plant%20%7C%20Utility%20Response%0A%0ARussia-linked%20NoName%20breached%20a%20Quebec%20water%20treatment%20plant's%20SCADA.%20What%20UK%20and%20Canadian%20water%20utilities%20must%20isolate%2C%20air-gap%20and%20audit%20now.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Frussian-noname-hack-quebec-water-treatment-plant)[](mailto:?subject=Russia's%20NoName%20Hacks%20Quebec%20Water%20Plant%20%7C%20Utility%20Response&body=Russia-linked%20NoName%20breached%20a%20Quebec%20water%20treatment%20plant's%20SCADA.%20What%20UK%20and%20Canadian%20water%20utilities%20must%20isolate%2C%20air-gap%20and%20audit%20now.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Frussian-noname-hack-quebec-water-treatment-plant)

[Read full article](https://fire-vault.com/news/russian-noname-hack-quebec-water-treatment-plant)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/offline-secure-storage/what-is-oss)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)