Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 28th September and 4th October 2026.📅 29th September
Australia’s next data breach could target these woefully porous government departments after alarming hack on Medicare by a rogue OpenAI agent
📅 28th September
16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data
29CM Data Breach Wider Than Reported, With 30,000 More Records Exposed
23,549 SIMBA Customers Have Identity Card Numbers, Phone Numbers and Other Details Exposed in Data Breach
23,549 Simba customers’ personal info leaked in data breach, including names & Identity Card numbers
80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
AI Ransomware Wiped 100 Azure Accounts in 7 Minutes: Only Pre-Configured Locks Survived
AI tests the limits of enterprise security governance
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Are Your Personal Data and Bank Details Safe? Cyberattacks Surge 27% as India Tops Asia-Pacific Threat List
Australia: Labor defends AI crackdown over Medicare data breach
Bank of Korea (BOK) faces scrutiny over cybersecurity after staff data breach
Bank of Korea Suffers Data Breach, Exposing 186 Employees' Information
Bitget Restarts Bitcoin Withdrawals Following $387.5 million Wallet Breach
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388 Million
Bright Smile Dental Care of Fishers notified of security breach
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
CISA orders feds to patch exploited Citrix flaws by Wednesday
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
Citrix NetScaler under active zero-day attack: critical patches available, 22K servers exposed
Citrix Patches Critical Zero Days Under Active Exploitation
Clicked A Fake Link? 6 Immediate Steps To Take After Falling For Phishing
Cyber attack takes L&Q’s online services down as correspondence from 12,000 residents hacked
Cyberattack Disrupts Police Systems in Wales, Staff Data Under Investigation
Cyberattack on Polish medical software provider exposes patient data
Cyberattack on Welsh Police Force May Have Exposed Data
Cyble Threat Report: August 2026 Hits Record High with 1,034 Global Ransomware Victims
Dartmouth College reaches $750,000 settlement following data breach affecting 96,000 members of the Dartmouth community
Data breach affects 23,549 customers of Singapore telco Simba, personal data protection commission investigating
Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns
Democratic Alliance (DA) to report e-Panic button data breach to Information Regulator of South Africa
District of Columbia (DC) Health Agency Exposes 400,000 Beneficiary Records
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Dutch police confirm arrest in ShinyHunters hacking investigation
Dutch 'reformed hacker' arrested in ShinyHunters investigation, police and boss say
Everything we know as East Suffolk and North Essex NHS Foundation Trust launch Noah Woods data breach probe
Ex-US soldier gets 70 months for role in AT&T, Snowflake data thefts
Fake Email Thread Tricks AI Summarizer Without Hidden Text
FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day
FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data
Finastra reaches $3.13 million settlement in data breach lawsuit
Fishers dental office reports ransomware attack on patient records
Flink hackers turn to customers, demanding ransom to keep their data off the dark web
Flock tries to nuke interactive map built from its own data leak
Football Leaks and the hacker behind Manchester City’s charges
Former Moores staff victims of severe cyber-attack
Former US soldier gets nearly six-year sentence for hacking, extorting telecoms
Gabia Data Breach Exposes Information of 2,998 Customers
Gallagher Transport Data Breach Exposes Social Security Numbers
Gyazo Data Breach Exposes 23.6 Million User Records and Nearly Half a Billion Image Metadata
Hackers Are Running Ransomware Like a Business. Companies Are Paying the Price
Hackers can hijack QR code domains to redirect users to phishing sites
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
How Ransomware Groups Are Adapting by Using Encrypted Exfiltration Methods
India Tops Asia-Pacific Ransomware Claims With 24 Victims In August
JadePuffer agentic AI attacks target Azure, destroy cloud resources
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
Japan Ransomware Activity Rises as Qilin Shows Signs of AI-Generated Tools
Japan travelers targeted by phishing scam mimicking hotel payment gateways
Kiteworks Systems Went Offline After Federal Threat Warning
Mass exploitation of Magento and Adobe Commerce critical flaw: 3,800+ online shops hacked
Model Context Protocol (MCP) Is Creating Major Governance Gaps, Researchers Warn
More than 23,000 Simba Customers’ Personal Info Leaked in Data Breach
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure
New Mexico jury finds Meta deceived consumers about data privacy practices
Noah Woods suspected data leak leaves NHS staff jobs at risk
Other users can watch your browsing and time your keystrokes through OS file notifications
Over 16,000 Supabase databases expose PII, passwords, auth tokens
Park24's Times Car Suffers Data Breach Affecting 6.6 Million Records, Including Driver's License Images
Pentagon Data Breach Exposes Unknown Number of Troops’ Social Security Numbers
Pentagon Data Breach and Kiteworks Targeted in Cyberattacks
Pentagon Data Breach Exposes Military Personnel
Pentagon data breach may affect 4 million
Personal information of over 23,500 Simba telco customers leaked in data breach in Singapore
Previously Convicted Dutch Hacker Arrested in ShinyHunters Odido Probe
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Quantum random numbers can pass the tests and still leak clues to attackers
Ransomware activity hits 2026 high as industrial sector bears 31% of attacks and Qilin dominates
Ransomware Attack Hits Japan's Keio Corporation Group, Disrupting Card Payments at Retail Stores
Ransomware attacks hit 2026 high: India most Targeted in Asia-Pacific
Ransomware attacks hit 2026 high in August; India most targeted in Asia-Pacific
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data
ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
ShinyHunters Hacks Rival Ransomware Gang Cl0p and Takes Over its Dark Web Tor Data Leak Site
Simba data breach: Personal information of over 23,500 customers leaked
Simba data breach compromises personal information of more than 23,500 customers
SIMBA data breach exposes 23,549 customer records
SIMBA data breach exposes Identity Card numbers and personal details of over 23,000 customers
Simba data breach exposes personal details of over 23,000 customers
South Africa: Democratic Alliance (DA) to report e-Panic data breach to Information Regulator
Stake and Revolut both impacted by third-party cyber attack
Tech Support Scam Kit Uses Google Ads to Deliver Fake Security Alerts
Ten NHS staff removed over Noah Woods data breach
The devil is still in the email - but wearing a new mask
The Hacker Who Beat Manchester City, and What It Means for Every Boardroom
The Two Biggest Threats to Cybersecurity in 2026: AI - and Not Having AI
Threat Actor Claims 37,000+ Israeli Identity Records Leaked via Ministry of Defense API
Two Citrix NetScaler Flaws Are Being Exploited for Remote Code Execution, CISA Urges Patching (CVE-2026-88771, CVE-2026-88772)
UK: Critical national infrastructure bodies to receive briefings on heightened Russia threats
US: Critical Infrastructure Braces for Sweeping New Cyber Reporting Rules
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
US, UK warn of exploited Citrix NetScaler zero-day bugs
Vendor hack exposes Bank of Korea staff data
World’s top ransomware group claims 2 more Australian victims
Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and
Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 14th September and 20th September 2026, kindly assisted by our partners.
