Breaking news

CySEC Enforces Regulatory Reforms To Safeguard Financial Markets

Withdrawal Of Administrative Services Licences

The Cyprus Securities and Exchange Commission (CySEC) has implemented a series of decisive regulatory actions in Cyprus. In a clear demonstration of its commitment to market integrity and compliance with financial services legislation, the regulator has withdrawn administrative services licences and initiated settlements with investment firms.

Fiduserve Management Limited And Mann Made Corporate Services

Effective September 9, 2025, Fiduserve Management Limited (LEI 213800WAVVOPS85N2205) formally waived its authorisation to provide administrative services under the Law Regulating Companies Providing Administrative Services and Related Matters of 2012. As a result, its licence (Number 215/196) expired and the firm was permanently removed from the licensed persons’ Register in accordance with section 16(2) of the Law.

Similarly, Mann Made Corporate Services (Cyprus) Limited ceased administrative services as of November 11, 2024, following the waiver of its authorisation (Number 200/196). The company was, in turn, permanently deregistered, further solidifying CySEC’s stringent supervisory approach.

Enforcement And Settlements With Investment Firms

In addition to licence revocations, CySEC detailed settlements with two investment firms over potential breaches of investment services legislation. On January 9, 2026, CySEC confirmed a settlement with EDR Financial Ltd (LEI 213800J8EV4SSMIBWB22). This settlement comes after an intensive investigation covering the period from 2020 to 2024, wherein the firm’s adherence to stringent organisational requirements and product intervention measures under Regulation (EU) No 600/2014 was scrutinised. The settlement fee of €50,000 has been fully paid by EDR Financial Ltd.

On the same date, a comparable settlement was reached with Benor Capital Ltd (LEI 213800SPTJ6JRLKCPY23) for non-compliance with the Investment Services and Activities and Regulated Markets Law of 2017, also resulting in a payment of €50,000. As emphasized by CySEC, all revenue collected from such settlements is channelled to the Treasury of the Republic, underscoring the regulator’s impartial role and commitment to fiscal transparency.

Commitment To Market Integrity

These regulatory actions not only reinforce CySEC’s robust supervisory framework but also serve as a stern reminder of the critical importance of adherence to established financial regulations. By swiftly addressing deviations from required standards, CySEC continues to protect market participants and ensure the integrity of Cyprus’ financial landscape.

Cyberattacks On Governments, Infrastructure And Businesses Shape 2026

Cybersecurity has become an increasingly prominent issue in 2026 as cyber incidents continue to affect governments, businesses and critical infrastructure worldwide. Recent attacks have targeted sectors ranging from healthcare and education to energy and public administration, highlighting the growing impact of cyber threats on economic activity and national security.

Questions Remain Over DOGE’s Access To Social Security Data

More than a year after individuals linked to the Elon Musk-led Department of Government Efficiency (DOGE) gained access to systems at the Social Security Administration, questions remain about how sensitive data was handled. Court proceedings are ongoing following allegations that a copy of the Social Security database was transferred to an external server, potentially exposing personal information belonging to millions of Americans.

According to legal filings, the Social Security Administration has acknowledged uncertainty regarding the contents of the server. Lawmakers have warned that, if confirmed, the incident could rank among the largest data breaches involving government records in U.S. history.

Hackers Increasingly Target Water Systems And Energy Grids

Cyberattacks targeting critical infrastructure have continued across Europe, including incidents affecting energy networks and water systems. Authorities in Poland, Sweden and Norway have reported attacks linked to groups believed to be acting in support of Russian interests. At the same time, tensions in the Middle East have heightened concerns about cyber threats to critical infrastructure, particularly privately operated utilities with limited cybersecurity resources.

Iranian Government Hackers Target Stryker

In March, Iranian hackers reportedly carried out a cyberattack against medical technology company Stryker, wiping thousands of employee devices. The incident, attributed to a group linked to Iranian intelligence, disrupted operations and affected the company’s first-quarter financial performance.

Instructure Among Shinyhunters’ Disruptive Hacking Campaigns

The hacking group ShinyHunters has continued to rely on voice phishing techniques to gain access to corporate networks. One of the most prominent incidents involved education technology company Instructure, whose Canvas learning management platform was breached.

The attack exposed personal information belonging to more than 30 million users and disrupted academic schedules during examination periods. Other reported victims include Charter, Carnival and organisations operating in the finance and public sectors.

Supply Chain Attacks Continue To Target Technology Companies

Software supply chains have remained a major target for cybercriminals. Security researchers have linked a series of attacks to compromises involving tools and platforms used by software developers, including Aqua Security’s Trivy, Bitwarden and Checkmarx. Such incidents can have wider consequences across the technology industry because compromised software updates may provide attackers with access to credentials and internal systems.

FBI Reports Major Cyber Incident

The Federal Bureau of Investigation was compelled to declare a “major cyber incident” in April after one of its surveillance systems was breached by actors believed to be linked to Chinese intelligence. This breach, which reportedly exposed the phone numbers of individuals under surveillance, has raised serious concerns about national security and the integrity of federal surveillance operations.

Hasbro Faces Operational Disruptions Following Cyberattack

Toy manufacturer Hasbro experienced weeks of operational disruption after detecting a cyberattack in late March. The company reported website outages and other operational challenges before confirming in May that the attackers had been removed from affected systems. Regulatory filing delays and other business impacts are expected to continue in the near term.

Millions Of Identity Documents Exposed

Several data exposure incidents reported during the year affected systems used for identity verification and customer onboarding. Cases involving a hotel check-in platform, a money transfer service, a prison communications provider and a UK visa portal exposed passports, driver’s licences and other identification documents belonging to more than two million people. The incidents have raised concerns about the security of personal information collected as part of identity verification requirements.

Growing Focus On Cybersecurity

The incidents reported throughout 2026 demonstrate the increasing impact of cyber threats across both public and private sectors. As organisations continue investing in digital infrastructure and artificial intelligence, cybersecurity remains a central concern for governments, businesses and critical service providers.

Aretilaw firm
The Future Forbes Realty Global Properties
eCredo
Uol

Become a Speaker

Become a Speaker

Become a Partner

Subscribe for our weekly newsletter