Liquid Network Hackers Demand Bug Fix Before Returning $320M BTC
![]()

![]()

![]()

![]()

![]()

![]()

![]()
A De Bijenkorf cyberattack involving one of the retailer's external logistics partners has disrupted order processing, returns, and refunds while raising concerns over potential customer data exposure. The Dutch luxury department store chain said the security incident occurred within the systems of a third-party logistics provider, adding that there is currently no evidence that its own infrastructure was compromised.
The Amsterdam-based retailer confirmed that customers can continue placing online orders and stores remain open. However, deliveries, returns, and refunds are expected to take longer than usual as the investigation continues.
According to De Bijenkorf, unauthorized individuals gained access to part of its logistics partner's systems. The logistics provider responded by immediately blocking the unauthorized access and implementing additional security measures.
An external investigation is now underway to determine the cause of the incident, its scope, and whether customer information was affected.
As a precaution, De Bijenkorf has informed customers about the incident and submitted a report to the Dutch Data Protection Authority while awaiting the investigation's findings.
The retailer said investigators are still determining whether any personal information has been compromised.
Based on the information currently available, data that may be involved includes:
De Bijenkorf emphasized that sensitive financial information is not part of the incident. The company said payment details, bank account numbers, credit card information, usernames, and passwords were not accessed.
The retailer said it is still investigating whether individual customers have been affected. Customers whose information is confirmed to be involved will receive direct communication via email from info@debijenkorf.nl.
For those who have not yet received a notification, the company said it cannot currently rule out the possibility that their information was included in the incident until the investigation is completed.
De Bijenkorf also stressed that no login credentials were compromised, meaning unauthorized individuals cannot access customer accounts using stolen usernames or passwords.
Although the investigation remains ongoing, De Bijenkorf warned customers to stay alert for a possible phishing risk if personal information is ultimately found to have been exposed.
The retailer advised customers not to click on suspicious links or open unexpected attachments. It also reminded customers never to share passwords, payment information, or personal details through email or phone calls.
The company said it will never request credit card details, gift card information, or other sensitive information via email.
The incident adds to a growing list of attacks targeting organizations that support retail operations rather than retailers directly. A logistics cyberattack can interrupt deliveries, returns, and customer service even when the affected retailer's own systems remain operational.
In July 2026, a ransomware attack on Japan's largest refrigerated logistics company disrupted food deliveries across the country, causing supply shortages for restaurant chains, including Kentucky Fried Chicken. The incident demonstrated how cyberattacks on logistics providers can quickly impact downstream retail operations and customer services.
For now, De Bijenkorf said its stores remain open, online ordering continues to operate, and there are no indications that its own systems have been compromised. The retailer said it will provide additional updates as the external investigation establishes whether customer data was affected and the full extent of the incident.

![]()
Chick-fil-A data security incident may have exposed personal and account information belonging to customers after unauthorized parties launched an automated attack against the company’s website and mobile application. The incident targeted certain Chick-fil-A One accounts between June 17 and June 19, 2026, using account credentials obtained from a third-party source.
Chick-fil-A said it identified suspicious login activity involving certain Chick-fil-A One accounts and immediately took steps to prevent further unauthorized access. The company launched an investigation and determined on July 13, 2026, that unauthorized parties may have accessed information stored in affected accounts.
The company notified affected customers about the incident and outlined the types of information that may have been involved, along with steps taken to secure accounts and protect customers.
According to the notice sent to customers, the Chick-fil-A data security incident involved an automated attack against the company's website and mobile application. The attackers used account credentials, including email addresses and passwords, that were obtained from a third-party source.
The activity took place over a three-day period between June 17 and June 19. After identifying suspicious login activity, Chick-fil-A moved to prevent additional unauthorized activity and began investigating the incident.
The company said its investigation later determined that unauthorized parties may have accessed information in customers' Chick-fil-A One accounts.
The information potentially accessed in the incident varied depending on what customers had stored in their accounts.
Potentially affected data may have included customers' names, email addresses, Chick-fil-A One membership numbers and mobile pay numbers. The information may also have included QR codes, the last four digits of credit or debit card numbers, and the amount of Chick-fil-A credit, such as an e-gift card balance, associated with an account.
For customers who had additional information saved to their accounts, the potentially exposed data may also have included the month and day of their birthday, phone number and address.
The company did not state that all listed information was accessed for every affected customer.
Following the incident, Chick-fil-A said it took immediate action to protect affected accounts. The measures included forcing log-outs from impacted accounts and removing stored payment methods.
The company also restored the balances of impacted Chick-fil-A One accounts. As an additional measure for affected customers, Chick-fil-A said it added rewards to their accounts.
The company said it continues to enhance its security, monitoring and fraud controls to reduce the risk of similar incidents in the future.
Chick-fil-A said it has reset the passwords associated with affected accounts and urged customers to update their passwords as soon as possible.
The company recommended that customers choose strong, difficult-to-guess passwords that are unique to their Chick-fil-A accounts and not reused across other websites or online services.
The company also encouraged customers to remain vigilant against potential identity theft and fraud. Customers were advised to review their credit reports and account statements carefully and check for any activity that they do not recognize.
The Chick-fil-A data security incident highlights the risks associated with compromised account credentials being used in automated attacks. While the company said it took steps to secure affected accounts and restore balances, customers are being encouraged to take additional precautions to protect their personal information and online accounts.

![]()
OpenAI and Hugging Face are investigating an AI security incident involving an AI agent that compromised infrastructure while models were being evaluated for advanced cyber capabilities. The incident was detected and contained after the models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure.
Hugging Face disclosed the incident last week, while OpenAI has now shared preliminary findings from its investigation. According to OpenAI, the activity involved a combination of models, including GPT 5.6 Sol and a more capable pre-release model, with reduced cyber refusals for evaluation purposes. The models were being tested against a benchmark designed to measure advanced cyber capabilities.
OpenAI described the incident as unprecedented and said it is continuing its investigation alongside Hugging Face. The company said the findings are being shared to help defenders understand what occurred and assess the capabilities of increasingly advanced AI models.
The incident took place during an internal evaluation designed to test models against advanced exploitation scenarios involving complex attack paths. OpenAI said the evaluation was conducted without production classifiers that normally prevent models from pursuing high-risk cyber activity.
The testing environment was designed to be highly isolated, with network access limited to package installation through an internally hosted third-party software system that functions as a proxy and cache for package registries.
Despite these restrictions, the models spent substantial inference compute attempting to obtain open Internet access. During this process, they identified and exploited a zero-day vulnerability in the package registry cache proxy. OpenAI said the vulnerability has since been responsibly disclosed to the vendor.
The models then carried out privilege escalation and lateral movement within the research testing environment until they reached a node with Internet access.
[caption id="attachment_113283" align="aligncenter" width="600"]After obtaining Internet access, the models inferred that Hugging Face could host models, datasets and solutions related to the ExploitGym evaluation. The models then searched for ways to obtain secret information that could help them bypass the evaluation.
In one example described by OpenAI, the models chained multiple attack vectors, including stolen credentials and zero-day vulnerabilities, to identify a remote code execution path on Hugging Face servers.
OpenAI's security team detected the anomalous activity internally. Hugging Face's security team and agents also detected and stopped the activity on its infrastructure. The company had already begun containment and forensic reconstruction using its own open-source models when the two organizations connected.
Both companies are continuing to investigate the incident and its impact.
As part of its response, OpenAI said it is implementing stricter infrastructure configuration controls while identified vulnerabilities are patched. The company acknowledged that these measures could come at the cost of research velocity and said its Safety and Security Committee is being briefed on the controls and their impact.
OpenAI is also working with Hugging Face on the forensic investigation and has responsibly disclosed the identified zero-day vulnerability in the internally hosted third-party software.
The company has also brought Hugging Face into its trusted access program and is supporting its teams in using AI model capabilities to strengthen defenses.
OpenAI said it is improving protections around future training and evaluations, including stronger safeguards for model alignment, cybersecurity and monitoring during internal testing. The company noted that deployment safeguards were intentionally disabled during this evaluation because the goal was to measure cyber vulnerabilities.
OpenAI said the incident demonstrates the need for AI security and safety measures to keep pace with rapidly advancing model capabilities. The company is strengthening containment, monitoring, access controls and evaluation practices used during model development.
The incident also highlights how advanced models can potentially discover and exploit novel attack paths in real-world systems without access to source code. OpenAI said increasingly capable models should also be used defensively to help security teams identify weaknesses, understand vulnerability chains and accelerate remediation.
Hugging Face CEO Clem Delangue said the incident demonstrates the importance of collaboration in addressing AI safety and security challenges. Both organizations said they will continue investigating the incident and share additional findings and best practices as the work progresses.

![]()

![]()

![]()

![]()

![]()

![]()

![]()

![]()