The week in breach news

Government agencies bore the brunt of this week’s cyberattacks, with the FBI declaring a major incident after a breach on its job application portal FBIJobs.gov, a separate attack on a Pentagon personnel database exposing personal information belonging to nearly three million individuals and the UK’s third-largest police force confirming it was hit by a cyberattack. Meanwhile, cryptocurrency exchange Bitget lost $388 million to attackers who exploited a third-party security vulnerability and Apple rushed out an emergency patch for a zero-day flaw that may have already been used in highly targeted attacks.

The week in breach news

United States

FBI

Industry: Government & Public SectorExploit: Hacking

The FBI reportedly declared a "major incident" and notified its agents and support staff after a cyberattack on its job application portal FBIJobs.gov.

Last week, the ShinyHunters ransomware group claimed it breached the FBI's job application portal and stole data on thousands of agents and applicants. The FBI has since issued an internal notification to staff confirming that names, addresses, job titles and Social Security numbers were exposed in the incident. Unusually, the hackers are not seeking a financial ransom but are instead demanding the correction of an earlier FBI-issued report that they claim misrepresents their activities.

The attack is the latest in a growing pattern of cyberattacks targeting U.S. federal agencies. The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a separate data breach only last month.

Source

How it could affect your business

Businesses that work with or alongside federal agencies should take note of this growing wave of cyberattacks targeting government systems. When agency data is compromised, the ripple effects can extend to contractors, partners and vendors who share data or systems with those agencies. Conducting regular third-party risk assessments, limiting the data shared with external partners to only what is strictly necessary and ensuring that any systems connected to government networks meet robust security standards are practical steps businesses can take to reduce their exposure.

United States

The Pentagon

Industry: Government & Public SectorExploit: Hacking

The FBI is also investigating a separate data breach at a Pentagon personnel database that may have exposed personal information belonging to close to three million individuals.

Between October 2025 and July 2026, a Defense Manpower Data Center (DMDC) information system experienced unauthorized access by some users. The DMDC serves as one of the Pentagon's main repositories for personnel records, holding information on active-duty and reserve troops, civilian employees, contractors, retirees, veterans and military family members. The breach affected 2.76 million living individuals and another 294,000 deceased persons, with exposed information including Social Security numbers and details about the jobs they held.

The scope and sensitivity of the exposed data could raise significant national security concerns, particularly given that the compromised files included details about the roles and responsibilities of military and civilian personnel.

Source

How it could affect your business

One of the most alarming aspects of this breach is that unauthorized access went undetected for nearly nine months, giving attackers an extended window to access and extract sensitive personnel records. The ability to detect an intrusion is just as important as preventing one in the first place. Continuous network monitoring, strict access controls and anomaly detection tools that flag unusual behavior early can significantly reduce the time an attacker spends inside a system undetected, limiting the damage before it compounds.

United Kingdom

Dyfed-Powys Police

Industry: Government & Public SectorExploit: Hacking

Dyfed-Powys Police, a territorial police force in Wales and the third largest police force in the UK, confirmed it was compromised in a cyberattack.

Dyfed-Powys covers the counties of Carmarthenshire, Ceredigion, Pembrokeshire and Powys in Wales. The force said it was hacked on September 14 in an incident that disrupted some non-emergency systems. While there was no evidence that personal data belonging to members of the public had been affected, the force acknowledged that staff information may have been accessed or compromised in the attack.

Online and email contact services were unavailable for a period following the attack but have since been restored. The force confirmed it remained fully operational throughout the incident and that its response to emergency calls was not affected.

Source

How it could affect your business

When staff information is compromised, it can expose personnel to targeted phishing, fraud and even physical safety risks, particularly in law enforcement, where officer identities may be sensitive. For public sector organizations, investing in robust network segmentation ensures that an attack on non-critical systems cannot cascade into more sensitive ones. Regular security audits, staff awareness training and clear incident response protocols are essential to maintaining public trust and operational continuity when an attack does occur.

Asia & Pacific

Bitget

Industry: FinanceExploit: Third-Party Data Breach

Cryptocurrency exchange Bitget confirmed that attackers stole approximately $388 million after exploiting a vulnerability in a third-party security product used by the exchange.

On September 24, Bitget noticed unauthorized transfers from some of its wallets and temporarily suspended customer withdrawals while it investigated. The stolen funds came from a portion of the exchange's hot and warm wallets, with cold wallets remaining unaffected. While most customer funds are kept in offline cold wallets, hot and warm wallets are used to process withdrawals, with transfers still requiring approval before they are signed.

Bitget has not disclosed exactly how the attacker gained initial access, but the investigation found that the attacker compromised a critical backend system within its wallet infrastructure and spoofed transaction data to trigger the approval process.

Source

How it could affect your business

This incident is a stark reminder that third-party solutions and services can become a direct pathway into your organization's most critical systems. Even when your own defenses are strong, a vulnerability in a vendor's product can be enough for an attacker to gain a foothold and cause significant damage. Organizations should thoroughly vet the security practices of any third-party solution they integrate into their infrastructure, ensure vendor contracts include clear security obligations and monitor third-party access closely for any unusual activity.

North America

Apple

Industry: TechnologyExploit: Zero-day vulnerability

Apple released iOS and macOS updates on September 28 to patch a zero-day vulnerability that may have been actively exploited in targeted attacks.

The flaw, tracked as CVE-2026-86950, is an out-of-bounds write issue in the CoreGraphics component that can be exploited for arbitrary code execution when processing a specially crafted file. While Apple has not disclosed how the malicious file is delivered, CoreGraphics handles 2D graphics and PDF rendering across the operating system, meaning it could potentially arrive via web pages, email attachments or messaging apps, where automatic attachment and link previews could enable zero-click exploitation.

Meanwhile, Apple confirmed it is aware of a report that the vulnerability may have been exploited in an extremely sophisticated attack targeting specific individuals on versions of iOS prior to iOS 27.

Source

How it could affect your business

While this flaw appears to have been exploited only in highly targeted attacks, it is strongly advised that all users install the latest security updates promptly to prevent potential ongoing attacks. Unpatched vulnerabilities, even those initially used in targeted campaigns, can quickly become a broader threat as details become more widely known among cybercriminals. Ensuring all devices across the organization are kept up to date is one of the most straightforward and effective steps businesses can take to stay ahead of emerging threats.

Like what you're reading?

Subscribe now to get security news and information in your inbox every week

Upcoming Webinars

Join other IT professionals to connect, learn and level up. Get insights into the latest cybersecurity trends and technologies.

Smarter MSP growth: Real stories, real results

Smarter MSP growth: Real stories, real results

View event
Kaseya Connect Local ∷ Cleveland

Kaseya Connect Local ∷ Cleveland

View event
Kaseya Security quarterly product innovation update

Kaseya Security quarterly product innovation update

View event