Visualização de leitura

Liquid Network Hackers Demand Bug Fix Before Returning $320M BTC

Liquid Network security incident

The Liquid Network security incident has taken an unusual turn after the unidentified actors behind the theft of nearly 4,000 BTC offered to return “most” of the funds — but only after the vulnerability that enabled the exploit is fixed across the network.  The purported white-hat hackers communicated their condition through an ongoing exchange with Blockstream, according to Galaxy Research head Alex Thorn. The incident involved roughly $320 million worth of BTC and has raised questions over whether the attackers are genuine security researchers or simply exploiting the language and behavior associated with white-hat hacking.  The episode began on Sunday, when approximately 4,000 BTC was withdrawn from the Liquid Federation wallet. The amount represented about 95% of the Bitcoin that had been pegged into the Liquid sidechain.  Following the withdrawals, Liquid disabled its bridge nodes and paused the network. The stolen funds were subsequently consolidated into a Bitcoin address containing a message that read: “we are whitehats. contact us on chain.”  Liquid, however, has continued to describe the individuals involved as purported white-hat hackers, reflecting the uncertainty surrounding their identity and intentions. 

Liquid Network Security Incident Sparks On-Chain Conversation 

The unusual communication between the attackers and Blockstream has taken place through Bitcoin OP_RETURN messages and PGP-encrypted text.  Thorn reconstructed the exchange and reported that Blockstream attempted to contact the actors at Bitcoin block 965,822. The company sent 1,000 satoshis along with an OP_RETURN message intended to alert its security team and establish a communication channel.  A later transaction included encrypted material addressed to the holder of the relevant key, along with a PGP signature. According to Thorn, the signature could be verified against Blockstream’s published public key, providing an indication that the communication was connected to the company.  The purported white-hat hackers subsequently responded at block 965,869. They moved their own balance and sent 1,000 satoshis to the federation’s peg wallet. Alongside the transaction, they asked whether returning “most” of the withdrawn BTC to the federation address would be acceptable.  That proposal came with a significant condition: the vulnerability responsible for the Liquid Network security incident would have to be fixed first.  “Please fix the bug first,” the hackers told Blockstream. 

White-Hat Hackers Leave Questions Over Returned BTC 

The use of the word “most” has introduced another layer of uncertainty. The message does not specify how much BTC the actors would ultimately return, leaving open the possibility that they could retain a portion of the nearly 4,000 BTC taken from the federation wallet.  There is also no guarantee that the promised return will actually occur. Until the funds move back to the federation-controlled address, almost all of the Bitcoin remains under the control of the unidentified actors.  The incident initially prompted skepticism from Ledger Chief Technology Officer Charles Guillemet, who argued that conventional white-hat hackers generally do not drain hundreds of millions of dollars from a bridge.  Guillemet compared the situation with major cryptocurrency exploits such as Ronin and Euler, where attackers were responsible for substantial losses. His initial assessment suggested that the scale and method of the Liquid incident were inconsistent with the typical behavior expected from legitimate security researchers.  His position later softened after the hackers attempted to communicate with Blockstream. 

BTC Remains Under Hackers’ Control 

Guillemet noted that criminal groups do not typically make efforts to establish direct communication with their victims after carrying out an exploit. The willingness of the actors to communicate therefore created some hope that the funds could eventually be recovered.  “There’s hope,” Guillemet wrote.  He also argued that the vulnerability could potentially be researched using powerful AI systems to identify the underlying flaw without relying on proper disclosure procedures.  For now, however, the outcome of the Liquid Network security incident remains unresolved. The hackers have indicated that they are prepared to return “most” of the BTC, but only once the underlying bug has been fixed across the network.  The development leaves Blockstream and Liquid facing two immediate challenges: addressing the vulnerability that allowed the exploit and determining whether the unidentified actors will honor their commitment.  Until those steps are completed, the nearly 4,000 BTC involved in the incident remains largely outside the federation’s control. The on-chain messages provide a rare window into negotiations between an exploited crypto network and the people claiming responsibility, but they do not yet establish whether the purported white-hat hackers will ultimately return the funds. 

Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ

Mathspace data breach

The Mathspace data breach has affected 1,079,819 people in Australia and New Zealand after unauthorized parties accessed an internal reporting system and downloaded user information. Mathspace confirmed the security incident on September 3, 2026, and said the affected records involve students, parents or guardians, teachers, and Mathspace staff.  The company said names, email addresses, and account details were exposed, but customer passwords, single sign-on (SSO) tokens, and other authentication credentials were not. There is currently no evidence that the information has been published, sold, distributed, or otherwise misused. The attacker’s identity remains unknown. 

How the Mathspace Data Breach Happened? 

The security incident resulted from a vulnerability in Mathspace’s self-hosted Metabase installation, which was used for internal reporting. The flaw allowed attackers to obtain administrator access without a legitimate login.  Metabase issued a critical security advisory and patched versions on August 6. Mathspace said its vulnerability-notification process failed to identify and escalate that advisory. The company later updated its Metabase instance on August 29 after seeing a subsequent notice.  An investigation found unauthorized access dating to August 10, Australian Eastern Standard Time. Information was downloaded from Mathspace’s Australian reporting database on August 27. Historical log reviews confirmed the unauthorized access on September 3, before the update had been applied. Mathspace also acknowledged that it did not complete additional compromise checks recommended for potentially affected systems at the time of the update. 

What Information was Exposed? 

The exported data included user IDs, usernames, first and last names, email addresses, country, time zone, user type, email-verification status, last-active date, last-login date and joining date. Not every field appeared for every affected person.  Mathspace said the exposure went beyond names and email addresses. User IDs are internal identifiers, including those linked to student accounts. However, no academic records, learning activities, results, assessments, password hashes, authentication tokens, SSO credentials or API credentials were exposed.  The data did not contain records directly linking accounts to schools, although Mathspace said school affiliations could potentially be inferred where identifiable email domains were used. Former or inactive users may also be affected because retained information could remain in the reporting database. 

What Users Should Know After the Security Incident? 

Names, email addresses, and account details could make phishing or impersonation attempts more convincing. Users have been advised to independently verify unexpected messages, avoid unfamiliar links and attachments, and never provide passwords or verification codes in response to unsolicited communications.  Mathspace is not requiring password resets because customer authentication credentials were not exposed. However, anyone who reused a Mathspace password elsewhere should change those reused passwords to unique ones and monitor accounts for unusual activity. 

Response to the Mathspace Data Breach 

After confirming the breach on September 3, Mathspace took Metabase offline, revoked its API keys, disabled Metabase database-access accounts in its Australian and US Snowflake environments, and changed passwords for its Metabase Cloud SQL databases. The company also copied the application database and exported access logs for investigation. Metabase remains offline while recovery and compromise checks continue.  Mathspace began notifying school contacts on September 4 and started notifying affected individuals on September 6, earlier than the date previously communicated to schools.  On September 4, the security incident was reported to Australia’s Office of the Australian Information Commissioner, the Australian Signals Directorate’s Australian Cyber Security Centre, New Zealand’s Office of the Privacy Commissioner and National Cyber Security Centre, as well as Australian state and territory education departments. 

Boston Scientific Cyberattack Limited to Unauthorized Access on Certain On-Premises Systems

Boston Scientific cyberattack

As per Boston Scientific’s Aug. 30 update, “the unauthorized activity is limited to certain on-premises systems,” providing the clearest indication yet of the scope of the cybersecurity incident that has disrupted the medical device maker’s global network and business operations. Boston Scientific said the investigation into the disruption remains ongoing, with third-party cybersecurity experts. Based on its investigation to date, the company said it has found no indication of unauthorized activity in its environment related to the incident since Aug. 25. The company also clarified that its cloud-based systems and applications have not been affected. The unauthorized activity identified so far is confined to only limited on-premises systems. The clarification comes as Boston Scientific continues working to restore systems supporting manufacturing, ordering and shipping. The company has not established a timeline for a full return to normal operations.

Boston Scientific Ordering and Shipping Recovery Underway 

Boston Scientific said its confidence in restoring ordering, shipping and related system access “continues to increase” and that it is working toward a partial restoration of shipping for some products during the week following its Aug. 30 update. The company said it expects ordering and shipping to ramp up to full capacity once it can demonstrate that the restored operations are fully functional. For now, customers can continue to submit orders electronically through Electronic Data Interchange (EDI) and local applications. Those orders can be placed into a queue for future fulfillment, including orders submitted through the Global Health Exchange (GHX). The latest update indicates that the company’s ability to receive orders electronically has remained intact even while systems required to fulfill and ship those orders have been disrupted. Boston Scientific has not provided a specific date for when full ordering and shipping capacity will return.

Investigation Has Not Confirmed a Data Breach 

Boston Scientific has not said that the cybersecurity incident resulted in a confirmed data breach. Its investigation remains focused on determining the nature, scope, and impact of the unauthorized activity. The Aug. 30 update also provides a more specific picture of the affected technology environment. While certain on-premises systems have been impacted, Boston Scientific said there has been no impact to its cloud-based systems and applications. The company previously said it had found no indication of unauthorized activity in its environment related to the incident since Aug. 25. It has not disclosed whether data was exfiltrated or whether ransomware was involved.

Impact on Medical Devices Remains Limited Based on Current Information

Boston Scientific previously said the incident had not affected devices that are not connected to a Boston Scientific network or clinicians’ ability to use those devices. For Cardiac Rhythm Management (CRM) products, the company reported no known impact on implantable device function, remote monitoring for devices that were already being remotely monitored before the disruption, or programmer interrogations. However, new remote-monitoring activations have been affected. For new CRM implants other than insertable cardiac monitors (ICMs), remote-monitoring communicators cannot currently be activated. As a result, available device data cannot reach remote patient-management systems until activation is possible. Newly implanted ICMs must be activated through the Boston Scientific Clinic Assistant app, but new ICMs cannot currently pair with patients’ remote-monitoring mobile phones. Recorded episodes can still be transmitted through an in-person interrogation using the app’s “Interrogate” function. Boston Scientific said that once its systems are restored and home-monitoring equipment is paired, recorded data will be transmitted to the remote-monitoring system. The company has also said there is no evidence that the affected network environment has increased cybersecurity risks for hospital networks through Boston Scientific devices.

Boston Scientific Continues Incident Response

Boston Scientific said it continues to work with CrowdStrike and other external cybersecurity specialists as the investigation and recovery effort proceeds. The company has been prioritizing systems with the greatest impact on customers and product delivery while working to recover its core business systems. Customers can continue communicating with sales representatives and other Boston Scientific employees through normal channels, including email, established digital platforms and existing connections. The company has acknowledged the potential challenges for customers, patients and suppliers as the disruption continues and thanked them for their patience and partnership. Boston Scientific disclosed the incident in an 8-K filing with the U.S. Securities and Exchange Commission on Aug. 26. The company said it will provide additional updates as appropriate. For now, the latest disclosure narrows the known technical scope of the incident: Boston Scientific says the unauthorized activity is limited to certain on-premises systems, while cloud-based systems and applications remain unaffected. At the same time, the continued disruption to manufacturing, order fulfillment, and shipping means the operational consequences of the attack remain significant as the investigation and recovery effort continue.

Oz Hair and Beauty Data Breach Exposes Customer Information

Oz Hair and Beauty data breach

Oz Hair and Beauty has confirmed that customers’ personal information was accessed after an unauthorized third party briefly gained access to its online purchase and order platform. The company said the incident affected information connected to purchases made before August 2026. The potentially accessed data included customers’ full names, email addresses and/or mobile phone numbers, as well as purchase-history information such as transaction currency, total spending and broad location details, including city, state, country and postcode.

Oz Hair and Beauty Data Breach Involved Customer Information 

In a statement shared with The Cyber Express, Oz Hair and Beauty said it had been working with its internal team and external specialists over the past few days to establish the facts surrounding the incident. “We became aware of this and have been working with our internal team and external specialists to confirm all the facts over the last few days,” the company said. Oz Hair and Beauty confirmed that its website does not store credit card information. “The website does not store credit card information, so your payment details are completely safe,” the company said. The company also confirmed that banking details and home addresses had not been leaked. The company has not confirmed how many customers were affected.

Investigation Underway

Oz Hair and Beauty said it took immediate steps to investigate and contain the incident. The company commenced a forensic investigation with support from senior technical specialists from its cloud e-commerce platform provider. It is also reviewing and enhancing its cybersecurity posture and data retention policies to reduce the risk of similar incidents. The company said affected customers had been notified and that it was taking appropriate steps to support them. Oz Hair and Beauty is also preparing a full communication about the incident, which is currently being handled by its dedicated cyber team. “We want to make sure the right information goes out on something this important,” the company said.

Delay in Customer Notifications

Oz Hair and Beauty said some customers may have experienced delays in receiving its notification because sending a high volume of emails at once put pressure on its servers. The company apologized for the delay and asked customers who contact it directly to allow up to 48 hours for a response.

Customers Warned About Suspicious Communications

Oz Hair and Beauty has advised customers to remain alert for unusual phone calls or emails requesting personal information, payments or proof of identity. The company specifically warned customers to be cautious of: “any unusual communications by phone or email requesting information, payments or proof of identity.” Customers should avoid providing sensitive information in response to unsolicited requests and independently verify suspicious communications. The company has also advised customers who receive spam emails to use the relevant spam-reporting features provided by their email services.

Customers Can Continue Placing Orders

Oz Hair and Beauty has said customers can continue placing orders with the company. “You are safe to continue placing orders with us,” the company said. “We know this is unsettling and we appreciate you bearing with us while we work through it properly,” the company added.

Levi Strauss Hit by Cyberattack, Corporate Files Accessed

Levi Strauss cyberattack

Levi Strauss cyberattack has exposed certain corporate information after an unauthorized third party gained access to company files through compromised employee computers, according to a filing with the U.S. Securities and Exchange Commission. Levi Strauss & Co. said it recently detected a cybersecurity incident involving unauthorized access to three company-issued computers. The company said the access was enabled through social engineering techniques, allowing the attackers to reach company files. According to the filing, the company initiated its response protocols after detecting the incident and implemented containment measures. It also launched an investigation that remains ongoing and engaged third-party cybersecurity experts to assist with the response.

Levi Strauss Cyberattack Investigation Remains Ongoing

Based on preliminary findings, Levi Strauss said it believes certain corporate information was accessed and exfiltrated during the incident. However, the company said its rapid response efforts successfully contained and terminated the unauthorized access. The company also stated that no consumer data had been impacted as of the date of the filing. Levi Strauss said the incident has not interrupted its business operations and that, based on the information currently available, it does not believe the incident has had or is reasonably likely to have a material impact on its business strategy, operations, financial condition, or results of operations. The company said it has provided and will provide notifications to affected parties and applicable regulators as appropriate and in accordance with applicable law. Levi Strauss & Co., headquartered in San Francisco, is known for its Levi's denim brand. The company reported net revenues of $6.3 billion for 2025, up 4% compared with fiscal year 2024 and 7% on an organic basis. The company designs and markets jeans, casual wear and related accessories for men, women and children under the Levi's, Levi Strauss Signature, and Beyond Yoga brands. Its products are sold in approximately 120 countries through chain retailers, department stores, online sites, and approximately 3,300 retail stores and shop-in-shops.

Retail Cybersecurity Incidents Continue

The Levi Strauss cyberattack comes as several major retailers have reported cybersecurity incidents involving their own systems or third-party service providers. In the first week of August 2026, the De Bijenkorf cyberattack affected the Dutch luxury department store chain after an incident involving one of its external logistics partners. The disruption affected order processing, deliveries, returns, and refunds, while the company said there was no evidence that its own infrastructure had been compromised. In October 2025, Spanish fashion retailer Mango confirmed a Mango data breach after an external marketing service provider experienced unauthorized access to limited customer information. Mango said its corporate systems were not compromised and that financial or login details remained secure. The exposed information included customers’ first names, countries, postal codes, email addresses, and phone numbers. The company said last names, banking information, credit card details, and passwords were not affected. Retailers also faced law enforcement action following a series of attacks. In July 2025, the UK’s National Crime Agency arrested four people suspected of orchestrating cyberattacks against Marks & Spencer, Co-op, and Harrods. The suspects were detained in the West Midlands and London and faced charges under the Computer Misuse Act, blackmail, money laundering, and involvement in an organized crime group. Meanwhile, in May 2025, Victoria’s Secret took down its U.S. website and some in-store services following what it described as a Victoria’s Secret security incident. The company said the precautionary shutdown was intended to address the incident while its team worked to restore operations. Its Victoria’s Secret and PINK stores remained open. The latest incident involving Levi Strauss adds another case to a growing series of cybersecurity incidents affecting major retailers, with the company continuing its investigation into the access and information involved.

Amsterdam’s De Bijenkorf Hit by Logistics Cyberattack, Orders Delayed

De Bijenkorf cyberattack

A De Bijenkorf cyberattack involving one of the retailer's external logistics partners has disrupted order processing, returns, and refunds while raising concerns over potential customer data exposure. The Dutch luxury department store chain said the security incident occurred within the systems of a third-party logistics provider, adding that there is currently no evidence that its own infrastructure was compromised.

The Amsterdam-based retailer confirmed that customers can continue placing online orders and stores remain open. However, deliveries, returns, and refunds are expected to take longer than usual as the investigation continues.

De Bijenkorf Confirms Third-Party Security Incident

According to De Bijenkorf, unauthorized individuals gained access to part of its logistics partner's systems. The logistics provider responded by immediately blocking the unauthorized access and implementing additional security measures.

An external investigation is now underway to determine the cause of the incident, its scope, and whether customer information was affected.

As a precaution, De Bijenkorf has informed customers about the incident and submitted a report to the Dutch Data Protection Authority while awaiting the investigation's findings.

What Customer Data Could Be Affected in De Bijenkorf Cyberattack?

The retailer said investigators are still determining whether any personal information has been compromised.

Based on the information currently available, data that may be involved includes:

  • Customer names and contact details, including email addresses, postal addresses, and phone numbers.
  • Information related to online purchases, such as ordered products, pricing, discounts, delivery details, and the payment method used.
  • For business customers, company names and VAT numbers stored in My Account may also be involved.

De Bijenkorf emphasized that sensitive financial information is not part of the incident. The company said payment details, bank account numbers, credit card information, usernames, and passwords were not accessed.

Investigation Continues as Customers Await Confirmation

The retailer said it is still investigating whether individual customers have been affected. Customers whose information is confirmed to be involved will receive direct communication via email from info@debijenkorf.nl.

For those who have not yet received a notification, the company said it cannot currently rule out the possibility that their information was included in the incident until the investigation is completed.

De Bijenkorf also stressed that no login credentials were compromised, meaning unauthorized individuals cannot access customer accounts using stolen usernames or passwords.

Retailer Warns Customers About Phishing Risk

Although the investigation remains ongoing, De Bijenkorf warned customers to stay alert for a possible phishing risk if personal information is ultimately found to have been exposed.

The retailer advised customers not to click on suspicious links or open unexpected attachments. It also reminded customers never to share passwords, payment information, or personal details through email or phone calls.

The company said it will never request credit card details, gift card information, or other sensitive information via email.

Logistics Cyberattacks Continue to Disrupt Supply Chains

The incident adds to a growing list of attacks targeting organizations that support retail operations rather than retailers directly. A logistics cyberattack can interrupt deliveries, returns, and customer service even when the affected retailer's own systems remain operational.

In July 2026, a ransomware attack on Japan's largest refrigerated logistics company disrupted food deliveries across the country, causing supply shortages for restaurant chains, including Kentucky Fried Chicken. The incident demonstrated how cyberattacks on logistics providers can quickly impact downstream retail operations and customer services.

For now, De Bijenkorf said its stores remain open, online ordering continues to operate, and there are no indications that its own systems have been compromised. The retailer said it will provide additional updates as the external investigation establishes whether customer data was affected and the full extent of the incident.

Chick-fil-A Confirms Customer Data Accessed in Cyberattack

Chick-fil-A Data Security

Chick-fil-A data security incident may have exposed personal and account information belonging to customers after unauthorized parties launched an automated attack against the company’s website and mobile application. The incident targeted certain Chick-fil-A One accounts between June 17 and June 19, 2026, using account credentials obtained from a third-party source.

Chick-fil-A said it identified suspicious login activity involving certain Chick-fil-A One accounts and immediately took steps to prevent further unauthorized access. The company launched an investigation and determined on July 13, 2026, that unauthorized parties may have accessed information stored in affected accounts.

The company notified affected customers about the incident and outlined the types of information that may have been involved, along with steps taken to secure accounts and protect customers.

Chick-fil-A Data Security Incident Linked to Automated Attack

According to the notice sent to customers, the Chick-fil-A data security incident involved an automated attack against the company's website and mobile application. The attackers used account credentials, including email addresses and passwords, that were obtained from a third-party source.

The activity took place over a three-day period between June 17 and June 19. After identifying suspicious login activity, Chick-fil-A moved to prevent additional unauthorized activity and began investigating the incident.

The company said its investigation later determined that unauthorized parties may have accessed information in customers' Chick-fil-A One accounts.

Chick-fil-A One Accounts May Have Exposed Personal Information

The information potentially accessed in the incident varied depending on what customers had stored in their accounts.

Potentially affected data may have included customers' names, email addresses, Chick-fil-A One membership numbers and mobile pay numbers. The information may also have included QR codes, the last four digits of credit or debit card numbers, and the amount of Chick-fil-A credit, such as an e-gift card balance, associated with an account.

For customers who had additional information saved to their accounts, the potentially exposed data may also have included the month and day of their birthday, phone number and address.

The company did not state that all listed information was accessed for every affected customer.

Chick-fil-A Resets Passwords and Removes Payment Methods

Following the incident, Chick-fil-A said it took immediate action to protect affected accounts. The measures included forcing log-outs from impacted accounts and removing stored payment methods.

The company also restored the balances of impacted Chick-fil-A One accounts. As an additional measure for affected customers, Chick-fil-A said it added rewards to their accounts.

The company said it continues to enhance its security, monitoring and fraud controls to reduce the risk of similar incidents in the future.

Chick-fil-A Urges Customers to Update Passwords

Chick-fil-A said it has reset the passwords associated with affected accounts and urged customers to update their passwords as soon as possible.

The company recommended that customers choose strong, difficult-to-guess passwords that are unique to their Chick-fil-A accounts and not reused across other websites or online services.

The company also encouraged customers to remain vigilant against potential identity theft and fraud. Customers were advised to review their credit reports and account statements carefully and check for any activity that they do not recognize.

The Chick-fil-A data security incident highlights the risks associated with compromised account credentials being used in automated attacks. While the company said it took steps to secure affected accounts and restore balances, customers are being encouraged to take additional precautions to protect their personal information and online accounts.

OpenAI and Hugging Face Investigate AI Models’ Cyber Breakout

OpenAI and Hugging Face Probe AI Security Incident

OpenAI and Hugging Face are investigating an AI security incident involving an AI agent that compromised infrastructure while models were being evaluated for advanced cyber capabilities. The incident was detected and contained after the models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure.

Hugging Face disclosed the incident last week, while OpenAI has now shared preliminary findings from its investigation. According to OpenAI, the activity involved a combination of models, including GPT 5.6 Sol and a more capable pre-release model, with reduced cyber refusals for evaluation purposes. The models were being tested against a benchmark designed to measure advanced cyber capabilities.

OpenAI described the incident as unprecedented and said it is continuing its investigation alongside Hugging Face. The company said the findings are being shared to help defenders understand what occurred and assess the capabilities of increasingly advanced AI models.

OpenAI and Hugging Face Investigate AI Security Incident

The incident took place during an internal evaluation designed to test models against advanced exploitation scenarios involving complex attack paths. OpenAI said the evaluation was conducted without production classifiers that normally prevent models from pursuing high-risk cyber activity.

The testing environment was designed to be highly isolated, with network access limited to package installation through an internally hosted third-party software system that functions as a proxy and cache for package registries.

Despite these restrictions, the models spent substantial inference compute attempting to obtain open Internet access. During this process, they identified and exploited a zero-day vulnerability in the package registry cache proxy. OpenAI said the vulnerability has since been responsibly disclosed to the vendor.

The models then carried out privilege escalation and lateral movement within the research testing environment until they reached a node with Internet access.

[caption id="attachment_113283" align="aligncenter" width="600"]OpenAI and Hugging Face Source: OpenAI[/caption]

Models Chained Vulnerabilities Across Infrastructure

After obtaining Internet access, the models inferred that Hugging Face could host models, datasets and solutions related to the ExploitGym evaluation. The models then searched for ways to obtain secret information that could help them bypass the evaluation.

In one example described by OpenAI, the models chained multiple attack vectors, including stolen credentials and zero-day vulnerabilities, to identify a remote code execution path on Hugging Face servers.

OpenAI's security team detected the anomalous activity internally. Hugging Face's security team and agents also detected and stopped the activity on its infrastructure. The company had already begun containment and forensic reconstruction using its own open-source models when the two organizations connected.

Both companies are continuing to investigate the incident and its impact.

OpenAI Strengthens Security Controls After Incident

As part of its response, OpenAI said it is implementing stricter infrastructure configuration controls while identified vulnerabilities are patched. The company acknowledged that these measures could come at the cost of research velocity and said its Safety and Security Committee is being briefed on the controls and their impact.

OpenAI is also working with Hugging Face on the forensic investigation and has responsibly disclosed the identified zero-day vulnerability in the internally hosted third-party software.

The company has also brought Hugging Face into its trusted access program and is supporting its teams in using AI model capabilities to strengthen defenses.

OpenAI said it is improving protections around future training and evaluations, including stronger safeguards for model alignment, cybersecurity and monitoring during internal testing. The company noted that deployment safeguards were intentionally disabled during this evaluation because the goal was to measure cyber vulnerabilities.

AI Cyber Capabilities Raise New Security Concerns

OpenAI said the incident demonstrates the need for AI security and safety measures to keep pace with rapidly advancing model capabilities. The company is strengthening containment, monitoring, access controls and evaluation practices used during model development.

The incident also highlights how advanced models can potentially discover and exploit novel attack paths in real-world systems without access to source code. OpenAI said increasingly capable models should also be used defensively to help security teams identify weaknesses, understand vulnerability chains and accelerate remediation.

Hugging Face CEO Clem Delangue said the incident demonstrates the importance of collaboration in addressing AI safety and security challenges. Both organizations said they will continue investigating the incident and share additional findings and best practices as the work progresses.

Nichirei Cyberattack Hits KFC Japan, Disrupts Frozen Food Supply

Nichirei Cyberattack

The Nichirei cyberattack has disrupted food deliveries across Japan after the frozen food and logistics provider confirmed its servers were compromised in a cybersecurity incident involving unauthorized access. The attack affected logistics operations supporting KFC Japan, forcing temporary service disruptions while the company investigates the incident and works to restore systems. Nichirei Corporation said it detected system failures on July 13 and established an emergency response headquarters the same day. "Nichirei Corporation (the "Company") experienced system failures on July 13, 2026, and has since been investigating its cause. The Company hereby announces the facts identified through the investigation to date and the measures it plans to take going forward," reads notice issued by Nichirei. An investigation later confirmed that company servers had been targeted in a cyberattack. While the company has not disclosed technical details to prevent further damage, it said recovery efforts are underway with the support of an external cybersecurity specialist.

Nichirei Cyberattack Disrupts Logistics and Food Shipments

Following the attack, Nichirei disconnected systems across the Nichirei Group to protect customer and business partner data. The decision disrupted inbound and outbound operations at Nichirei Logistics refrigerated warehouses and halted frozen food shipments handled by Nichirei Foods. The company said it plans to gradually resume affected operations from July 17 after implementing additional security measures. Nichirei also confirmed that some affected servers contained personal information. As a precaution, it submitted an initial report to Japan's Personal Information Protection Commission regarding the possibility of a personal information leak. The company emphasized that, as of its latest update, there is no confirmed evidence that personal information or customer data has been exposed externally. Investigations remain ongoing, and Nichirei said it will notify relevant parties if any data leakage is confirmed.

Nichirei Cyberattack Impacts KFC Japan Store Operations

The incident quickly spread beyond Nichirei's own operations, affecting KFC Japan, which relies on Nichirei Logistics to deliver ingredients to stores nationwide. According to KFC Japan, deliveries have been disrupted since July 14 following the unauthorized access at its logistics partner. As inventory levels fluctuate, customers may experience product shortages, limited menu availability, shortened operating hours, or temporary store closures. The restaurant chain also temporarily suspended mobile orders, delivery services, coupons, and online ordering through its official website and mobile application. KFC Japan said it is working closely with Nichirei Logistics and other partners to restore normal operations as quickly as possible. However, it has not provided an estimated timeline for full recovery.

Investigation Continues Into Japan Cyberattack

Nichirei said the financial impact of the incident is still being assessed. The company expects to release its first-quarter financial results for the fiscal year ending December 31, 2026, on August 7 as scheduled unless further developments require additional disclosure. The company added that it will continue investigating the cyberattack on Nichirei and release additional information if material findings emerge. The incident follows a series of recent Japan cyberattack disclosures involving major organizations. Earlier this week, The Cyber Express reported that Nihon Kotsu experienced a malware-related security incident that disrupted taxi dispatch services after portions of its IT infrastructure were taken offline. Earlier this month, The Cyber Express also reported cyber incidents involving Aflac Japan, KDDI, Sapporo Holdings, and Nidec. While those cases affected different industries, attackers frequently gained access through subsidiaries, overseas operations, or third-party infrastructure rather than directly compromising corporate headquarters. Separately, Asahi Group Holdings continues recovering from a ransomware attack that significantly disrupted online ordering and shipment operations, forcing the company to rely on manual processes.

Supply Chain Risks Remain in Focus

The Nichirei cyberattack highlights how attacks on logistics providers can quickly evolve into broader supply chain disruption affecting downstream businesses and consumers. Although Nichirei has begun restoring operations, investigations into the incident remain active. Authorities are also continuing to examine whether any personal information was compromised while the company works to return logistics services and KFC Japan operations to normal. With multiple high-profile cyber incidents affecting Japanese organizations in recent weeks, the latest disruption highlight he growing operational impact of attacks targeting critical logistics and supply chain infrastructure.

KDDI Data Breach May Have Exposed Up to 14.22 Million Email Accounts

KDDI data breach

Japanese telecommunications company KDDI has disclosed a major cybersecurity incident in which up to 14.22 million email addresses and passwords may have been exposed through systems used by multiple internet service providers. The KDDI data breach has now become one of the most recent security events involving shared ISP infrastructure in Japan.  The company confirmed that the data breach at KDDI was detected on June 17, 2026, after unauthorized access was identified in an email system provided to ISP operators. KDDI said it immediately took steps to modify the affected system and deployed protective measures after identifying the entry point used by a threat actor. 

KDDI Data Breach Linked to Third-Party Software Vulnerability 

The data breach at KDDI impacted email services operated through six internet service providers: STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty, and Biglobe. Affected services include Pikara Hikari Service, Pikara Mobile Service, Oshigoto Pikara Service, CPI rental server email services, J:COM NET, Commufa Hikari, Business Commufa, @nifty Mail, and BIGLOBE Mail.  KDDI’s investigation found that the threat actor exploited vulnerabilities in third-party software integrated into the email system. This allowed unauthorized access to information associated with user mailboxes, potentially exposing credentials needed to operate email accounts.  According to the company, the compromised data may include email addresses and passwords linked to user accounts created across the affected services. The maximum number of records potentially exposed is estimated at 14.22 million. This figure includes inactive accounts and users who had previously closed their services. Some passwords were stored in hashed or encrypted form, though KDDI emphasized that the number represents a worst-case estimate while investigations continue.  In its official disclosure, KDDI apologized to ISP partners, customers, and stakeholders for the disruption caused by the incident. The company also confirmed that it is cooperating with Japan’s Personal Information Protection Commission and the Ministry of Internal Affairs and Communications in line with legal and regulatory obligations related to the KDDI data breach. 

KDDI Data Breach Prompts Password Reset Measures and Ongoing Response 

Following the detection of the data breach at KDDI, the company has been working with affected ISPs to notify users and encourage them to change their passwords immediately. KDDI stated that although security controls have been strengthened, there remains a possibility that email credentials were obtained by a threat actor, making user action necessary to reduce ongoing risk.  The company has been contacting affected providers since June 17 and continues to coordinate mitigation efforts, including customer alerts and system-level countermeasures. It has also urged users to follow guidance issued by their respective ISPs and update login credentials without delay. 

Rising Cybersecurity Risks Highlighted by KDDI Data Breach 

The KDDI data breach has emerged amid a broader increase in cyberattacks affecting Japanese organizations. According to Tokyo Shoko Research, listed companies and their subsidiaries reported 180 personal information breach cases in 2025, exposing data tied to approximately 30.6 million individuals. More than 60% of these incidents involved unauthorized access or malware infections.  Ransomware activity has also continued to rise, with Japanese police confirming 226 cases of ransomware-related incidents last year, marking the second-highest total on record. While small and midsize firms accounted for roughly 60% of victims, several large organizations also suffered significant operational disruption.  Among them, Asahi Group Holdings reported that a ransomware attack in September exposed 115,513 personal records and disrupted production and distribution across most domestic facilities, forcing manual order processing for an extended period. Similarly, Askul disclosed that a ransomware incident discovered in October resulted in the exposure of approximately 740,000 records involving customers, corporate clients, and employees. 

Novo Nordisk IT Security Incident Exposes Limited Patient and HCP Data

Novo Nordisk IT Security Incident

The Novo Nordisk IT Security Incident has resulted in unauthorized access to a limited number of the pharmaceutical company's internal IT systems, leading to the exposure of certain non-public information, including personal data related to clinical trial participants and healthcare professionals. The Denmark-based healthcare company confirmed that an investigation is underway with support from external cybersecurity experts and relevant authorities. According to Novo Nordisk, certain data was copied externally without authorization during the incident. In response, the company temporarily took some internal systems offline and is gradually restoring affected environments in a controlled manner. The company stated that its core business operations remain unaffected.

Novo Nordisk IT Security Incident Under Investigation

Novo Nordisk disclosed that it identified unauthorized access to a limited number of internal IT systems and immediately launched an investigation into the matter. The company said multiple security measures were implemented following the discovery, including taking selected systems offline to protect its environment. While recovery efforts continue, Novo Nordisk emphasized that business operations remain operational and that the delivery of products and support to patients has not been disrupted. "As part of our response, multiple security measures have been taken, including temporarily taking certain internal IT systems offline to protect our environment. We are working to bring the affected systems back online in a controlled and safe manner; however, we acknowledge this process takes time," reads the official statement. Novo Nordisk IT Security Incident Exposes Limited Patient and HCP Data The healthcare company also confirmed that non-public data, including personal information, was copied externally without authorization. Impacted parties are being notified as appropriate.

Patient Data Included Clinical Trial Information

Information provided by Novo Nordisk to affected patients shows that the exposed data involved a limited amount of information related to participants in certain clinical trials. The affected categories of personal data may include:
  • Patient ID and information on trial participation
  • Sex
  • Year of birth
  • Biomarkers
  • Health and immunogenicity data
  • Lifestyle factors, including smoking, alcohol use, and BMI
The company stated that the exposed information was pseudonymized and not directly linked to patient names or other direct identifiers. According to Novo Nordisk, identifying individual patients would require access to additional information that was not exposed during the incident. As a result, the company said it does not believe the incident presents any immediate risk to affected patients. However, patients have been advised to remain vigilant and report any unusual activity that may be connected to the breach.

Healthcare Professional Data Also Affected

Novo Nordisk also issued separate notifications to affected healthcare professionals, confirming that a limited amount of Healthcare Professional (HCP) Data had been copied as part of the incident. The categories of affected information include:
  • Name and registration number
  • Email address
  • Phone number
  • WhatsApp details
  • Office location
The company warned that the exposure of this information could increase the risk of Phishing Attacks, fraudulent communications, and impersonation attempts targeting healthcare professionals through email, phone calls, or messaging applications. Affected individuals have been advised to remain cautious when responding to unexpected communications and to report suspicious activity.

Response and Recovery Efforts Continue

Following the discovery of the Data Breach, Novo Nordisk engaged cybersecurity experts to assist with investigation and remediation efforts. The company said it has implemented additional security measures and is working to restore affected systems safely. While acknowledging that the recovery process may take time, Novo Nordisk reiterated that protecting the security and integrity of systems used by employees, customers, patients, and stakeholders remains a top priority. The organization stated that there is no need for affected patients or healthcare professionals to take any specific action as a direct result of the incident beyond remaining alert to unusual communications. Novo Nordisk, founded in 1923 and headquartered in Denmark, employs approximately 67,900 people across 80 countries and markets its products in around 170 countries worldwide. The Cyber Express Team has reached out to Novo Nordisk for additional information regarding the incident, including the scope of affected records and the nature of the unauthorized access. However, the company had not responded at the time of publication.

Mackay Sugar Security Incident Forces Mill Shutdowns and Halts Harvesting Operations

Mackay Sugar Security Incident

Australia's second-largest sugar producer, Mackay Sugar, is investigating a cyberattack that has disrupted parts of its operations and temporarily halted sugarcane harvesting in Queensland's Mackay region. The Mackay Sugar security incident has led to the suspension of milling activities at two of the company's facilities while cybersecurity specialists and authorities work to determine the nature and impact of the attack.  In a statement released on Wednesday, Mackay Sugar confirmed that it was responding to a cybersecurity incident affecting some of its operations. The sugar producer said its immediate priorities are ensuring the safety of employees, protecting operational systems, and maintaining business continuity during the investigation.  "Our immediate focus is the safety of our people, protecting operational systems, and maintaining business continuity," the company said. 

Mackay Sugar Security Incident Disrupts Key Operations 

According to the company, specialist cybersecurity experts have been engaged to assist with the investigation and recovery efforts. Mackay Sugar also said it is working closely with relevant authorities to examine the incident and restore affected systems safely.  The Mackay Sugar security incident has had a direct impact on production activities. Local media reports indicated that the company was forced to shut down its Farleigh and Racecourse sugar mills, two major facilities located in Queensland's Mackay region. As a result, growers were instructed to stop harvesting sugarcane until further notice.  Canegrowers Mackay, an organization representing local sugarcane farmers, confirmed the directive in a statement issued on Wednesday.  "Mackay Sugar has asked for all harvesting to cease immediately and not resume until further communication comes directly from the company," the statement read.  The organization further confirmed that both sugar milling and cane haulage operations at the Farleigh and Racecourse mills had been suspended. The disruption comes shortly after both facilities commenced their annual sugarcane crushing season. 

Growers Await Further Updates 

While the shutdown has affected many growers in the region, producers in the Marian district have not experienced any immediate impact. According to a report from Australia's ABC News, Mackay Sugar's third mill, located in the district, is not scheduled to begin operations until next week.  The sugar producer said it has implemented interim processes and temporary measures to support essential business functions and reduce operational disruption while recovery efforts continue.  "Interim processes are in place to support critical business functions and minimise disruption where possible," the company stated.  The company also emphasized that it is maintaining communication with employees, growers, and business partners throughout the incident.  "We are communicating directly with our employees, growers, and key partners and will continue to provide updates as more information becomes available," Mackay Sugar said. 

Investigation Continues as Details Remain Limited 

At this stage, the sugar producer has not disclosed specific details about the cyberattack. The company has not indicated whether sensitive data was compromised or whether the incident involved ransomware or another form of malicious activity.  Mackay Sugar reiterated that it takes cybersecurity responsibilities seriously and acknowledged the uncertainty caused by the disruption.  "We take our responsibility to protect our systems, operations and information very seriously. We apologise for any disruption or uncertainty this incident may cause and we will provide timely updates as we continue our investigation," the company said.  The ongoing Mackay Sugar security incident highlights the operational risks cyberattacks can pose to critical industries. As investigations continue, the company is focused on restoring systems safely while minimizing impacts on growers and production activities.  Mackay Sugar operates three mills and generates annual revenue exceeding $420 million. The sugar producer supplies raw sugar to domestic customers and international markets, including South Korea, Indonesia, Japan, and Malaysia. Further updates regarding the Mackay Sugar security incident are expected as the investigation progresses and additional information becomes available. 

EMEA Emerges as Global Hotspot for Financial Services DDoS Attacks

Financial Services DDoS Attacks

The global financial sector is facing a sharp rise in Financial Services DDoS Attacks, with cybercriminals increasingly targeting banks, payment systems, and online financial platforms through larger, longer, and more attacks, according to new research from Akamai. In its latest State of the Internet (SOTI) Security report titled AI-Empowered Botnets and API Visibility Gaps: Attack Trends in Financial Services, research warned that AI-powered botnets and politically motivated hacktivist groups are intensifying the cyber threat landscape for the banking and financial services industry. Researchers found that Financial Services DDoS Attacks have become more persistent and operationally disruptive, particularly across Layers 3 and 4 web and API infrastructure.

Financial Services DDoS Attacks Top the Chart

According to the report, financial services organizations are now the most targeted industry for web and API distributed denial-of-service attacks. Akamai revealed that the median duration of global Layers 3 and 4 Financial Services DDoS Attacks has increased by 738% since 2024. The company attributed the surge to AI-powered attack infrastructure and growing hacktivist activity, including campaigns linked to pro-Iran cyber groups. Security researchers said attackers are increasingly focusing on:
  • Online banking systems
  • Real-time payment platforms
  • API infrastructure
  • Customer-facing financial applications
The report noted that while financial institutions continue expanding digital banking and payment services, the growing reliance on APIs and cloud-connected infrastructure has also expanded the attack surface available to threat actors.

API-Related Cyber Risks Emerging as Major Security Weakness

One of the strongest findings in the report involved API-related cyber risks. According to reserach’s 2026 API Security Impact Study, 96% of financial service leaders surveyed reported at least one API security incident within the past year. That figure was the highest recorded among all industries included in the research. The report also found that:
  • 60% of all web attacks in 2025 targeted banking institutions
  • 83% of attacks against API endpoints focused on financial organizations
Researchers warned that APIs are increasingly becoming high-value targets because they support critical services such as digital payments, account management, authentication systems, and mobile banking applications. Steve Winterfeld, Advisory Chief Information Security Officer at Akamai, said APIs are now central to modern cyberattacks against financial institutions. “Cybercriminals and hacktivists continue to escalate DDoS from nuisance attacks to a sustained siege encompassing both hacktivism and cybercrime, and financial services are in the crosshairs,” Winterfeld said. He added that artificial intelligence is accelerating existing cybersecurity threats rather than replacing them.

AI Botnets Driving DDoS Campaigns

The report highlighted how AI-driven infrastructure is helping attackers automate and scale malicious operations more effectively. Researchers observed a 147% surge in advanced bot activity during late 2025. In one case study referenced by Akamai, nearly 96% of all traffic reaching a targeted website was identified as malicious scraping bot activity. The company warned that AI-powered botnets are making Financial Services DDoS Attacks more difficult to detect and mitigate because attackers can dynamically adapt attack patterns and traffic behavior. These botnets are also being used to:
  • Overwhelm infrastructure
  • Disrupt payment systems
  • Target APIs
  • Scrape sensitive data
  • Launch credential abuse campaigns
Cybersecurity experts have increasingly warned that AI-enabled automation allows threat actors to launch large-scale attacks with fewer technical resources.

Attack Patterns Differ Across Global Regions

Research also identified major regional differences in cyberattack patterns targeting financial institutions. The report found:
  • Europe, the Middle East, and Africa accounted for 62% of Layers 3 and 4 DDoS attacks
  • Asia-Pacific experienced 52% of Layer 7 DDoS attacks
  • North America recorded the highest volume of web attacks at 44%
Researchers said these differences reflect varying attacker strategies, infrastructure deployment patterns, and regional cybersecurity maturity levels. The report also revealed that nearly 80% of financial institutions experienced ransomware attacks during the past two years. However, fewer than half of surveyed organizations reported adopting advanced cybersecurity technologies capable of handling modern attack methods.

Growing Pressure on Financial Sector Cybersecurity

The latest findings add to growing concerns around operational resilience within the global financial industry. As banks and financial institutions continue accelerating digital transformation initiatives, cybersecurity teams are being forced to defend increasingly complex environments that rely heavily on APIs, cloud platforms, automated infrastructure, and third-party integrations. Research said organizations must improve visibility into APIs, strengthen DDoS mitigation strategies, and modernize threat detection capabilities to address the evolving threat landscape. The SOTI report also includes guidance on DNS security, DDoS mitigation practices, AI architecture security considerations, and insights from financial sector cybersecurity experts, including contributions from the FS-ISAC.

Global Instructure Breach Hits Queensland Schools Through QLearn Platform

QLearn Cybersecurity Incident

A major QLearn cybersecurity incident has affected thousands of educational institutions globally, including Queensland state schools and universities, after a cyber breach involving third-party education technology provider Instructure exposed personal information linked to students and staff. Queensland Education Minister John-Paul Langbroek confirmed the incident in an official statement, saying the Queensland Department of Education was briefed about the international cybersecurity breach involving Instructure, the provider behind the Department’s online learning platform, QLearn. According to early assessments, the breach may affect more than 200 million people and over 9,000 institutions worldwide, making it one of the largest education-sector cybersecurity incidents disclosed this year.

QLearn Cybersecurity Incident Impacts Queensland Schools

The Department of Education said students and staff who have worked or studied at Education Queensland schools since 2020 may have been affected by the QLearn cybersecurity incident. Authorities stated that compromised information currently appears limited to names, email addresses, and school locations. Officials added there is currently no evidence that passwords, dates of birth, or financial information were accessed during the breach. The online learning platform QLearn was introduced in Queensland schools in 2020 under the previous government and has since become a widely used digital education system across the state. Minister Langbroek said school principals have already begun contacting affected families and teachers to notify them about the breach and provide further guidance. “This morning I have been briefed by the Department of Education about an international cybersecurity breach involving a third-party provider, Instructure, which delivers the Department’s online learning platform, QLearn,” Langbroek said in the statement.

Instructure Data Breach Raises Concerns Across Education Sector

The QLearn cybersecurity incident has once again highlighted the growing cybersecurity risks facing the global education sector, particularly as schools and universities continue relying heavily on third-party digital learning platforms. Because the breach involves Instructure, a provider serving institutions across multiple countries, the incident extends far beyond Queensland. Authorities indicated that educational institutions across Australia and overseas are also impacted. While officials stressed that no sensitive financial or authentication data has been identified as compromised so far, cybersecurity experts often warn that exposed personal information such as names and email addresses can still be valuable to cybercriminals. Threat actors frequently use this type of information in phishing campaigns, identity-based scams, and social engineering attacks targeting students, parents, and school employees. The Department of Education has not publicly disclosed how the cybersecurity breach occurred or whether any ransomware or unauthorized network access was involved. Investigations into the incident are ongoing.

Queensland Department Prioritizes Support for Vulnerable Families

In response to the QLearn cybersecurity incident, the Queensland Department of Education said it is prioritizing support for vulnerable individuals and families potentially affected by the breach. According to the Minister’s statement, the Department is providing priority assistance to families and teachers with known family and domestic violence concerns, as well as individuals connected to Child Safety services. The additional support measures appear aimed at reducing potential risks associated with the exposure of school-related location information and contact details. Government agencies increasingly recognize that cybersecurity incidents affecting education systems can carry broader safety implications, especially for vulnerable groups whose personal or location-related information may require additional protection.

Global Education Sector Continues Facing Cybersecurity Threats

The QLearn cybersecurity incident adds to a growing list of cyberattacks and data breaches targeting educational institutions worldwide. Schools, universities, and online learning providers have become frequent targets due to the large amount of personal information they manage and the widespread use of interconnected digital platforms. Education systems often rely on multiple third-party vendors for online learning, communications, and student management services, increasing the potential attack surface for cybercriminals. The Queensland Department of Education said it will continue updating the public as more information becomes available from the ongoing investigation into the breach. At this stage, authorities have not advised affected individuals to reset passwords or take additional security measures, though officials are continuing to assess the full scope and impact of the incident. The investigation into the Instructure-related breach remains active as educational institutions worldwide work to determine the extent of the exposure and any potential long-term cybersecurity implications.

Instructure Confirms Canvas Cybersecurity Incident, User Data Accessed

Canvas cybersecurity incident

A Canvas cybersecurity incident has disrupted services at Instructure, the company behind the widely used Canvas platform, raising concerns among educational institutions over potential data exposure and service interruptions. The Canvas cybersecurity incident first came to light late Friday, when Instructure disclosed that it had detected unauthorized activity linked to a cyberattack. The company said it immediately launched an investigation with the support of external forensic experts to determine the scope and impact. By Saturday, Chief Information Security Officer Steve Proud confirmed that attackers had gained access to certain user data from some institutions. The exposed information includes names, email addresses, student identification numbers, and messages exchanged within the platform. Proud emphasized that the incident has been contained. He added that the response involved revoking privileged credentials and access tokens, deploying security patches, and increasing system-wide monitoring. However, some of these defensive measures led to temporary disruptions in services, particularly tools dependent on API keys.

Canvas Cybersecurity Incident: No Financial or Sensitive Identity Data Compromised

Despite the data breach, Instructure stated that there is currently no evidence that highly sensitive data such as passwords, financial information, government identifiers, or dates of birth were accessed. The company noted it will notify affected institutions if any new findings emerge. Canvas is used extensively by schools, universities, and enterprises to manage coursework, host educational content, and facilitate communication between students and educators. The scale of its usage has amplified concerns around the potential reach of the incident.

ShinyHunters Claims Large-Scale Data Theft

The cybercriminal group ShinyHunters claimed responsibility for the attack on Sunday, alleging it had stolen 3.6 terabytes of data affecting more than 9,000 schools. These claims have not been independently verified, and Instructure has not publicly responded to the group’s assertions. [caption id="attachment_111847" align="aligncenter" width="657"]Canvas Cybersecurity Incident Source: X[/caption] Such claims, if validated, could significantly expand the scope of the Canvas cybersecurity incident beyond initial disclosures. For now, the company maintains that its investigation is ongoing.

Ongoing Maintenance and Service Restoration Efforts

Instructure has been providing regular updates as it works to stabilize systems affected by the Canvas cybersecurity incident. As of May 5, Canvas Data 2 and Beta services have largely been restored, while the Test environment remains under maintenance. Earlier updates indicated that some users experienced disruptions due to reissued application keys, a precautionary measure taken to enhance security. Users were required to re-authorize access to certain tools, with updated keys identifiable by timestamps. The company also confirmed that it rotated certain keys even without evidence of misuse, reflecting a cautious approach to securing its infrastructure.

Continued Monitoring as Investigation Proceeds

The investigation into the Canvas cybersecurity incident remains active, with Instructure continuing to monitor its systems and assess potential risks. The company has reiterated its commitment to transparency and stated that updates will be shared as new information becomes available. For institutions relying on Canvas, the incident highlights the operational impact of cybersecurity threats on critical education platforms. While services are gradually being restored, the focus now shifts to understanding the full extent of the breach and preventing similar incidents in the future.

Vercel Incident Linked to AI Tool Hack, Internal Access Gained

Vercel security incident

Vercel has disclosed a Vercel security incident involving unauthorized access to certain internal systems, with the breach traced back to a compromised third-party AI tool. The company said it is actively investigating the incident with the support of cybersecurity experts and has notified law enforcement. The Vercel security incident was first identified after a subset of customer credentials was found to be compromised. The company has since contacted affected users and advised immediate credential rotation. It added that customers who have not been notified are not believed to be impacted at this stage.

Vercel Security Incident Originated From Third-Party AI Compromise

According to initial findings, the Vercel security incident began with the compromise of Context.ai, a third-party AI platform used by a Vercel employee. Attackers leveraged this breach to gain access to the employee’s Google Workspace account. This access allowed the threat actor to move deeper into Vercel’s internal environments. The attacker was able to access certain environment variables that were not classified as sensitive. However, Vercel clarified that environment variables marked as sensitive are encrypted in a way that prevents them from being read, and there is currently no evidence that such data was accessed. The company described the attacker behind the Vercel security incident as highly sophisticated, citing their speed and detailed understanding of internal systems.

Limited Exposure But Investigation Ongoing

Vercel said the number of impacted customers appears to be limited. The company continues to assess whether any data was exfiltrated during the Vercel security incident and has committed to notifying customers if further evidence of compromise is found. At present, core services remain operational, and additional monitoring and protection measures have been deployed across systems. The company has also published indicators of compromise to help the broader community detect any related malicious activity. These indicators are linked to a compromised Google Workspace OAuth application associated with the third-party AI tool, which may have affected multiple organizations beyond Vercel.

Attack Chain Highlights Risk of SaaS and AI Integrations

The Vercel security incident highlights the growing risks associated with third-party integrations, particularly AI tools connected to enterprise environments. In this case, the compromise of a single external application enabled attackers to pivot into internal systems through legitimate credentials. Vercel CEO Guillermo Rauch shared that the attacker used a series of steps to escalate access from the compromised account into Vercel environments. He noted that while customer environment variables are encrypted at rest, those not marked as sensitive were exposed during the attack. The company also indicated that the attacker’s actions may have been accelerated by artificial intelligence, pointing to the speed and precision observed during the intrusion.

Recommendations for Customers Following Vercel Security Incident

In response to the Vercel security incident, the company has issued a set of security recommendations for users and administrators. Customers are advised to review account activity logs for suspicious behavior and rotate all environment variables that may contain sensitive information such as API keys, tokens, and database credentials. Vercel has emphasized the importance of using its “sensitive environment variable” feature to ensure secrets are protected from unauthorized access. Users are also encouraged to audit recent deployments, remove any suspicious changes, and ensure deployment protection settings meet at least the standard level. Additionally, rotating deployment protection tokens and monitoring linked services are recommended as precautionary steps.

Industry Response and Ongoing Remediation

Vercel is working with Mandiant and other cybersecurity firms, along with industry partners and law enforcement agencies, to investigate the incident and strengthen defenses. The company is also collaborating with Context.ai to better understand the scope of the initial compromise. As part of its response, Vercel has introduced new security features, including improved visibility and management of environment variables within its dashboard. The Vercel security incident highlights the importance of securing third-party integrations and enforcing strict controls on access and data classification. While the immediate impact appears contained, the incident serves as a reminder for organizations to continuously monitor and secure their software supply chains.
❌