Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ




This week, sophisticated cyber criminals attempted a password-recovery attack on hundreds of thousands of X users. X disrupted the attack to prevent user accounts from being captured. But, as we’ve shown, the Justice Department will stop at nothing in its pursuit of cyber fraudsters and scammers. We are working closely with @X to track down the criminals behind this week’s attack. There is no refuge for those that perpetrate their criminal schemes from behind computer screens."The attorney general did not disclose additional technical details about the cyberattack on X users, including how the attackers attempted to exploit the recovery system, whether any individual accounts were compromised, or where the suspected criminals were operating from. The DOJ investigation is intended to identify those responsible for the attempted intrusion, with Blanche emphasizing that authorities would pursue individuals involved in cyber fraud and scams even when those activities are conducted remotely.













A De Bijenkorf cyberattack involving one of the retailer's external logistics partners has disrupted order processing, returns, and refunds while raising concerns over potential customer data exposure. The Dutch luxury department store chain said the security incident occurred within the systems of a third-party logistics provider, adding that there is currently no evidence that its own infrastructure was compromised.
The Amsterdam-based retailer confirmed that customers can continue placing online orders and stores remain open. However, deliveries, returns, and refunds are expected to take longer than usual as the investigation continues.
According to De Bijenkorf, unauthorized individuals gained access to part of its logistics partner's systems. The logistics provider responded by immediately blocking the unauthorized access and implementing additional security measures.
An external investigation is now underway to determine the cause of the incident, its scope, and whether customer information was affected.
As a precaution, De Bijenkorf has informed customers about the incident and submitted a report to the Dutch Data Protection Authority while awaiting the investigation's findings.
The retailer said investigators are still determining whether any personal information has been compromised.
Based on the information currently available, data that may be involved includes:
De Bijenkorf emphasized that sensitive financial information is not part of the incident. The company said payment details, bank account numbers, credit card information, usernames, and passwords were not accessed.
The retailer said it is still investigating whether individual customers have been affected. Customers whose information is confirmed to be involved will receive direct communication via email from info@debijenkorf.nl.
For those who have not yet received a notification, the company said it cannot currently rule out the possibility that their information was included in the incident until the investigation is completed.
De Bijenkorf also stressed that no login credentials were compromised, meaning unauthorized individuals cannot access customer accounts using stolen usernames or passwords.
Although the investigation remains ongoing, De Bijenkorf warned customers to stay alert for a possible phishing risk if personal information is ultimately found to have been exposed.
The retailer advised customers not to click on suspicious links or open unexpected attachments. It also reminded customers never to share passwords, payment information, or personal details through email or phone calls.
The company said it will never request credit card details, gift card information, or other sensitive information via email.
The incident adds to a growing list of attacks targeting organizations that support retail operations rather than retailers directly. A logistics cyberattack can interrupt deliveries, returns, and customer service even when the affected retailer's own systems remain operational.
In July 2026, a ransomware attack on Japan's largest refrigerated logistics company disrupted food deliveries across the country, causing supply shortages for restaurant chains, including Kentucky Fried Chicken. The incident demonstrated how cyberattacks on logistics providers can quickly impact downstream retail operations and customer services.
For now, De Bijenkorf said its stores remain open, online ordering continues to operate, and there are no indications that its own systems have been compromised. The retailer said it will provide additional updates as the external investigation establishes whether customer data was affected and the full extent of the incident.



A Beneficial Owners Register breach has exposed data copies linked to approximately 31,000 legal entities after unknown attackers gained unauthorized access to the Register of Beneficial Owners (VwbP). Authorities confirmed the cyberattack prompted an immediate response, including taking the affected system offline, launching a technical investigation, and establishing a government-led crisis team to manage the incident.
According to official information, the attackers digitally accessed the VwbP during the night of July 30, 2026. Irregularities were detected later that day by the Office of Justice, which then contacted the Office of Information Technology to investigate the incident. Based on the initial findings, the affected system was immediately secured and removed from external access while investigators began a detailed analysis.
On July 31, 2026, the government was informed that the Beneficial Owners Register breach may have been successful. The first confirmed findings from the preliminary investigation were submitted on the afternoon of August 1.
Authorities said the attackers unlawfully accessed the directory and stole data copies relating to approximately 31,000 legal entities. The Register of Beneficial Owners (VwbP) stores information about the beneficial owners of companies, foundations, and trusts.
Officials stated that the register has been temporarily taken offline for external users through the LLV.li website while investigations continue. Based on current findings, there is no indication that any information stored in the system was altered or deleted during the incident.
Following confirmation of the incident, the government convened a crisis team on the evening of August 1, 2026. The team immediately began its work and was formally confirmed on August 2.
The crisis team is led by Prime Minister Brigitte Haas and Justice Minister Emanuel Schädler. According to the government, its priorities are to fully investigate the incident, inform affected individuals, and implement appropriate countermeasures.
Authorities confirmed that the incident qualifies as a data breach involving personal information under Article 33 of the General Data Protection Regulation (GDPR).
The crisis team said it is working to notify affected individuals in accordance with Article 34 GDPR as quickly as possible. A central information point is also being established to respond to questions from those impacted by the breach.
The Register of Beneficial Owners (VwbP) was established to support money laundering prevention and combat terrorist financing. It contains information identifying the beneficial owners of legal entities, including companies, foundations, and trusts.
The register operates under the Law on the Register of Beneficial Owners of Legal Entities (VwbPG), which came into force in 2021 to implement the requirements of the 5th EU Anti-Money Laundering Directive.
Authorities continue to investigate how the unauthorized access occurred and whether additional measures will be required to strengthen the security of the register. At this stage, officials have confirmed only that data copies were accessed and that there is currently no evidence suggesting records within the system were modified or deleted.

