The week in breach news

User data is again in the spotlight this week, with more than 16.7 million people caught up in two major breaches hitting Denmark’s national civil registry and Ukraine’s largest grocery chain, ATB. Meanwhile, a ransomware attack shut down Osaka Metropolitan University, South Korean banks are under investigation following signs of AI-assisted hacking and online retailer Asos is investigating unauthorised access to its customer notification platform.

The week in breach news

Europe

Denmark CPR

Industry: Government & Public SectorExploit: Hacking

Denmark's Central Person Register (CPR) is notifying approximately 8.8 million people that their personal information was stolen in a data breach.

CPR is Denmark's national civil registration system, containing information on around 11 million people, including residents, emigrants and deceased individuals. On October 5, CPR announced that hackers exploited a Danish company's lawful access to the system to exfiltrate personal information. Under Danish law, private companies with a legitimate interest are granted access to the CPR to obtain information on specific individuals.

The organization confirmed that the attackers accessed the names, addresses and CPR numbers, the equivalent of Social Security numbers, of approximately 8.8 million registered individuals, both living and deceased.

Source

How it could affect your business

The exposed information gives attackers everything they need to commit long-term identity fraud, opening fraudulent accounts, taking out loans or impersonating individuals in ways that can take years to unravel. Businesses should remind customers and employees to monitor their credit reports and financial accounts closely for unusual activity and to act quickly by placing a fraud alert or credit freeze if they suspect their information has been misused.

Europe

ATB

Industry: RetailExploit: Hacking

Ukraine's largest grocery store chain, ATB, confirmed on October 5 that it was hit by a cyberattack after hackers posted an extortion demand directly on its website.

A hacker group calling itself DataSuckers claimed responsibility for the attack and demanded $400,000, threatening to publish data it claims to have stolen from millions of ATB customers. A countdown timer accompanying the ransom demand appeared on the retailer's website before being later removed.

ATB denied that any customer data was compromised and temporarily took some online services offline, describing the action as routine technical maintenance. The group claimed to have obtained data belonging to 7.9 million customers, including names, phone numbers, email and physical addresses, password hashes, as well as employees' passport information and records of more than 11 million orders.

Source

How it could affect your business

Public-facing extortion demands, like the countdown timer posted directly on ATB's website, are a growing tactic used by attackers to maximize pressure on organizations and force a quick payout. Paying, however, is never a guarantee that stolen data won't still be published or sold. Businesses are far better positioned when they have a robust incident response plan and a solid business continuity and disaster recovery (BCDR) strategy in place, allowing them to manage the fallout of an attack without being backed into a corner by an extortion deadline.

Asia & Pacific

Osaka Metropolitan University

Industry: EducationExploit: Ransomware & Malware

Osaka Metropolitan University, one of Japan's largest universities, canceled classes and shut down a large part of its IT infrastructure following a suspected ransomware attack that began late last week.

On October 6, the university confirmed that the outage left its internal network, email and a range of administrative and academic systems unavailable. Osaka Metropolitan University said it believes ransomware caused the disruption and is investigating the attack with the assistance of outside cybersecurity specialists. It has not yet identified the attackers or confirmed whether a ransom demand was received.

The outage affected systems used for academic administration, educational support, financial accounting, payroll, human resources and library services, as well as the university's websites and internal network.

Source

How it could affect your business

When academic, administrative, financial and HR systems all share the same network, one breach can bring everything down at once with no quick workaround. Segmenting critical systems, maintaining offline backups and having a tested recovery plan in place are essential steps that can significantly limit the damage when an attack hits.

Asia & Pacific

South Korean banks

Industry: FinanceExploit: Hacking

South Korea's Financial Services Commission (FSC) confirmed a data breach at several South Korean banks, including Shinhan Bank and KB Kookmin Bank.

Shinhan Bank and KB Kookmin Bank are large private South Korean commercial banks, each holding more than $400 billion in assets. Authorities launched on-site investigations after receiving incident reports from the affected institutions. In some of the incidents, signs have emerged of AI being used as part of the attack.

However, authorities have not yet disclosed details on what kind of AI tools were used in the hacking incidents or the full scale of the breaches.

Source

How it could affect your business

Cybercriminals are increasingly using AI to automate attacks, identify vulnerabilities faster, craft more convincing phishing attempts and evade traditional detection tools. This means that defenses built around recognizing known attack patterns may no longer be sufficient. Investing in AI-driven threat detection tools that can identify and respond to unusual behavior in real time is becoming a critical part of any modern security strategy.

United Kingdom

Asos

Industry: RetailExploit: Third-Party Data Breach

Online fashion retailer Asos is investigating unauthorized access to its app system after shoppers received a notification claiming hackers had fully compromised its data.

Asos confirmed it is investigating unauthorized activity involving a third-party platform it uses to communicate with customers. The company said it took immediate action to restrict access to the notification platform and is working with internal and external specialist advisers as well as all relevant authorities.

The company confirmed that its website and app are operating as normal, with no current disruption to any aspect of its operations.

Source

How it could affect your business

A breach notification landing directly in customers' inboxes or on their devices, whether legitimate or not, can do immediate and lasting damage to customer trust. Shoppers who receive alarming messages about their data being compromised are likely to lose confidence in the brand, regardless of how the situation is ultimately resolved. Retailers and consumer-facing businesses should have a clear, pre-prepared communications plan that allows them to respond quickly, transparently and consistently across all channels when an incident occurs, reassuring customers and limiting reputational fallout before it takes hold.

Like what you're reading?

Subscribe now to get security news and information in your inbox every week

Upcoming Webinars

Join other IT professionals to connect, learn and level up. Get insights into the latest cybersecurity trends and technologies.

Autotask Answers Q4 Series

Autotask Answers Q4 Series

View event
Ask the Experts: Identity & User Security Q4 Series

Ask the Experts: Identity & User Security Q4 Series

View event
Cybersecurity Summit: What a hacker sees that you don’t

Cybersecurity Summit: What a hacker sees that you don’t

View event