Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 28th September and 4th October 2026.📅 29th September
17.3 Trillion Microsoft Records Exposed
A fake journalist used a real Calendly link to phish a tech founder
Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials
Apple patches CoreGraphics zero-day flaw exploited in attacks
Apple patches zero-day exploit possibly used in “extremely sophisticated” attacks
Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)
Australia’s next data breach could target these woefully porous government departments after alarming hack on Medicare by a rogue OpenAI agent
Automated AI agent used to breach cybersecurity nonprofit Dutch Institute for Vulnerability Disclosure (DIVD)
Critical Authlib authentication bypass flaw leaves countless apps in danger
Deepfakes at schools overwhelmingly target girls and women – and most involve explicit content
Deepfakes become a board priority once an executive falls for one
Forget Me Not: Connecticut’s New Privacy Law Collides With OSINT and Threat Intelligence
Former ShinyHunters hacker arrested in what could be an elaborate frame job in FBI hack
GitHub’s AI agent found 24 Android app vulnerabilities
Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider
Japanese Railway Operators Hit with Weekend Cyber Attacks
Kiteworks patches critical flaw, brings customer systems online
Kiteworks Urges Customers to Restart Systems After Shutdown Notice
Malicious Custom GPT on chatgpt.com lures users into installing a RAT
Microsoft Warns NeedyMantis Malware Enables Persistent Network Access
NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions
OpenAI’s GPT-6 Astra ran supply chain attacks despite being told not to
Pentagon Data Breach - Hackers Reportedly Accessed 3 Million People’s Sensitive Data
Pentagon Data Breach Exposes Social Security Numbers, Military Job Details
Popular games on Google Play contain trackers from Russia, China, and Israel, study finds
RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model
ShinyHunters says they “never intended or planned to” publish FBI data
Teen Hacker Finds Auth Flaw in Microsoft System With 17.3 Trillion Data Rows
Vietnamese man charged in $16 million 'pig butchering' crypto scam
What can a person find about you in an hour?
📅 28th September
16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data
29CM Data Breach Wider Than Reported, With 30,000 More Records Exposed
44 State Attorneys General Reach Data Breach Settlement With Lapcorp
23,549 SIMBA Customers Have Identity Card Numbers, Phone Numbers and Other Details Exposed in Data Breach
23,549 Simba customers’ personal info leaked in data breach, including names & Identity Card numbers
80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
AI Ransomware Wiped 100 Azure Accounts in 7 Minutes: Only Pre-Configured Locks Survived
AI Security Agents Struggle With Complex Bugs and Safe Patching
AI tests the limits of enterprise security governance
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Are Your Personal Data and Bank Details Safe? Cyberattacks Surge 27% as India Tops Asia-Pacific Threat List
Arizona court data breach: Cyberattack targets judicial network, protective orders
Australia: Labor defends AI crackdown over Medicare data breach
Bank of Korea (BOK) faces scrutiny over cybersecurity after staff data breach
Bank of Korea Suffers Data Breach, Exposing 186 Employees' Information
Bitget Restarts Bitcoin Withdrawals Following $387.5 million Wallet Breach
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388 Million
Bright Smile Dental Care of Fishers notified of security breach
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
CISA orders feds to patch exploited Citrix flaws by Wednesday
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
Citrix NetScaler under active zero-day attack: critical patches available, 22K servers exposed
Citrix Patches Critical Zero Days Under Active Exploitation
Clicked A Fake Link? 6 Immediate Steps To Take After Falling For Phishing
Clop ransomware gang moves to new server after Grav CMS vulnerability exploited
Cyber attack takes L&Q’s online services down as correspondence from 12,000 residents hacked
Cyberattack Disrupts Police Systems in Wales, Staff Data Under Investigation
Cyberattack on Polish medical software provider exposes patient data
Cyberattack on Welsh Police Force May Have Exposed Data
Cyble Threat Report: August 2026 Hits Record High with 1,034 Global Ransomware Victims
Dartmouth College reaches $750,000 settlement following data breach affecting 96,000 members of the Dartmouth community
Data breach affects 23,549 customers of Singapore telco Simba, personal data protection commission investigating
Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns
Democratic Alliance (DA) to report e-Panic button data breach to Information Regulator of South Africa
District of Columbia (DC) Health Agency Exposes 400,000 Beneficiary Records
Dutch man arrested in ShinyHunters investigation alleged to have been 'reformed hacker'
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Dutch police arrest security professional in ShinyHunters investigation
Dutch police confirm arrest in ShinyHunters hacking investigation
Dutch 'reformed hacker' arrested in ShinyHunters investigation, police and boss say
Everything we know as East Suffolk and North Essex NHS Foundation Trust launch Noah Woods data breach probe
Ex-US soldier gets 70 months for role in AT&T, Snowflake data thefts
Fake American Express “non‑compliance” phishing scam targets Australians
Fake Email Thread Tricks AI Summarizer Without Hidden Text
FBI grapples with fallout from massive data breach
FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day
FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data
Finastra reaches $3.13 million settlement in data breach lawsuit
Fishers dental office reports ransomware attack on patient records
Flink hackers turn to customers, demanding ransom to keep their data off the dark web
Flock tries to nuke interactive map built from its own data leak
Football Leaks and the hacker behind Manchester City’s charges
Former Moores staff victims of severe cyber-attack
Former US soldier gets nearly six-year sentence for hacking, extorting telecoms
Gabia Data Breach Exposes Information of 2,998 Customers
Gallagher Transport Data Breach Exposes Social Security Numbers
Gyazo Data Breach Exposes 23.6 Million User Records and Nearly Half a Billion Image Metadata
Hackers Are Running Ransomware Like a Business. Companies Are Paying the Price
Hackers can hijack QR code domains to redirect users to phishing sites
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
How Ransomware Groups Are Adapting by Using Encrypted Exfiltration Methods
India Tops Asia-Pacific Ransomware Claims With 24 Victims In August
JadePuffer agentic AI attacks target Azure, destroy cloud resources
JadePuffer criminals hijacked Azure identities and used them to blow up cloud resources
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
Japan Ransomware Activity Rises as Qilin Shows Signs of AI-Generated Tools
Japan travelers targeted by phishing scam mimicking hotel payment gateways
Japan's Keio confirms ransomware attack disrupted business systems
Kiteworks Systems Went Offline After Federal Threat Warning
Mass exploitation of Magento and Adobe Commerce critical flaw: 3,800+ online shops hacked
Model Context Protocol (MCP) Is Creating Major Governance Gaps, Researchers Warn
More than 3 million people affected by military data breach
More than 23,000 Simba Customers’ Personal Info Leaked in Data Breach
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure
New Mexico jury finds Meta deceived consumers about data privacy practices
Noah Woods suspected data leak leaves NHS staff jobs at risk
OpenAI reportedly ditches model over safety concerns
Other users can watch your browsing and time your keystrokes through OS file notifications
Over 16,000 Supabase databases expose PII, passwords, auth tokens
Park24's Times Car Suffers Data Breach Affecting 6.6 Million Records, Including Driver's License Images
Pentagon Data Breach Exposes Unknown Number of Troops’ Social Security Numbers
Pentagon Data Breach and Kiteworks Targeted in Cyberattacks
Pentagon Data Breach Exposes Military Personnel
Pentagon data breach may affect 4 million
Personal information of over 23,500 Simba telco customers leaked in data breach in Singapore
Previously Convicted Dutch Hacker Arrested in ShinyHunters Odido Probe
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Quantum random numbers can pass the tests and still leak clues to attackers
Ransomware activity hits 2026 high as industrial sector bears 31% of attacks and Qilin dominates
Ransomware Attack Hits Japan's Keio Corporation Group, Disrupting Card Payments at Retail Stores
Ransomware attacks hit 2026 high: India most Targeted in Asia-Pacific
Ransomware attacks hit 2026 high in August; India most targeted in Asia-Pacific
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
Renfe Cyberattack Hits Spain’s Rail Network as AI Role Probed
Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data
ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
ShinyHunters Hacks Rival Ransomware Gang Cl0p and Takes Over its Dark Web Tor Data Leak Site
ShinyHunters Says FBI Data Won’t Be Leaked When Ultimatum Ends
Simba data breach: Personal information of over 23,500 customers leaked
Simba data breach compromises personal information of more than 23,500 customers
SIMBA data breach exposes 23,549 customer records
SIMBA data breach exposes Identity Card numbers and personal details of over 23,000 customers
Simba data breach exposes personal details of over 23,000 customers
South Africa: Democratic Alliance (DA) to report e-Panic data breach to Information Regulator
Stake and Revolut both impacted by third-party cyber attack
Tech Support Scam Kit Uses Google Ads to Deliver Fake Security Alerts
Ten NHS staff removed over Noah Woods data breach
The devil is still in the email - but wearing a new mask
The Hacker Who Beat Manchester City, and What It Means for Every Boardroom
The Two Biggest Threats to Cybersecurity in 2026: AI - and Not Having AI
Threat Actor Claims 37,000+ Israeli Identity Records Leaked via Ministry of Defense API
Times Car confirms data breach affecting 6.6 million user accounts
Two Citrix NetScaler Flaws Are Being Exploited for Remote Code Execution, CISA Urges Patching (CVE-2026-88771, CVE-2026-88772)
UK: Critical national infrastructure bodies to receive briefings on heightened Russia threats
US: Critical Infrastructure Braces for Sweeping New Cyber Reporting Rules
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
US, UK warn of exploited Citrix NetScaler zero-day bugs
Vendor hack exposes Bank of Korea staff data
World’s top ransomware group claims 2 more Australian victims
Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and
Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 14th September and 20th September 2026, kindly assisted by our partners.
