SecureFact – September 28, 2026
Major cybersecurity incidents impacted online retailers, government agencies, cryptocurrency, software, ecommerce, and identity-verification organizations, exposing sensitive financial, personal, employee, customer, and identity data while highlighting risks from AI-powered attacks, zero-day vulnerabilities, compromised third-party applications, and large-scale data breaches.
Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
A financially motivated threat actor used open-source AI agent frameworks (Strix, Cairn, and Hermes) to attack hundreds of online retailers at scale, stealing more than 600,000 valid credit card records from two companies. The campaign has been active since at least July 2026 and was ongoing as of September 22. Between September 10-15, the attacker launched 105 distinct attack waves, succeeding on at least 27 targets. Credit card skimmers were injected into target websites using various methods including appending malicious code to JavaScript files, adding script tags to checkout pages, poisoning S3/CDN content, modifying database fields, and altering Kubernetes deployments. The attacker compromised at least 119 websites with credit card skimmers and targeted large organizations including a Fortune 500 hospitality company and a major U.S. airline. Researchers gained access to a staging server and retrieved direct evidence of the stolen credit cards. The attacker instructed AI agents to run cleanup procedures that removed card data from Magento databases after exfiltration, causing operational disruptions at several retailers. Mitigation included law enforcement involvement and coordination with cybersecurity experts at Gambit.
(Source: Read full report)
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing between 2TB and 3TB of sensitive data. The threat actors claimed they accessed FBI Criminal Justice, HR, Medlink, and additional services during the intrusion. The stolen data includes information on current and former FBI employees, job applicants, and other internal records. ShinyHunters shared a screenshot showing the FBI Jobs website defaced with their Umbreon Pokémon logo and a message claiming that FBI employee and applicant information had been compromised. The defacement message stated that sensitive personally identifiable and health-related information (PII/PHI) belonging to FBI employees and applicants had been stolen. The threat actors shared two sample records with BleepingComputer allegedly associated with FBI personnel, though authenticity was not independently verified. The FBI confirmed it is investigating the claims and immediately took affected systems offline upon detection. The company notified Services Australia on September 10 after validating the activity and investigating what information the agents accessed. Law enforcement involvement and system isolation were key mitigation steps taken by the FBI.
(Source: Read full report)
Hackers steal $351.6 million in Bitget crypto exchange hack
Cryptocurrency exchange Bitget disclosed that suspected North Korean hackers stole $351.6 million from its hot and warm wallets. The company discovered the breach Thursday evening after its security systems flagged multiple unauthorized transfers from a limited number of crypto wallets. The incident involved the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains and affected multiple assets including ETH, XRP (single-chain loss is the largest), BNB, AVAX, USDT, USDC, and other tokens. The attacker compromised a critical backend system within the wallet infrastructure, used it to spoof transaction data, and triggered the authorization process to move funds out. Bitget temporarily suspended all withdrawals while investigating the incident with help from law enforcement agencies, on-chain security institutions, and cybersecurity experts at Mandiant and SlowMist. The company’s User Protection Fund (holding 5,500 BTC currently worth about $464 million) will cover all losses. Bitget confirmed that its self-custodial Bitget Wallet was not affected as it operates on independent infrastructure. Based on IP behavior patterns and on-chain analysis, the attack method is highly consistent with known patterns of North Korean hacker organizations. The company reported the incident to relevant institutions and is fully cooperating in conducting a global investigation.
(Source: Read full report)
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Sweden’s data privacy regulator, IMY, imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. Miljödata is a Swedish software company that develops and provides work environment and HR management systems used by 80% of Sweden’s municipal systems. The cyberattack disrupted IT services in over 200 regions and compromised residents’ sensitive data including personal identity numbers, contact information, sickness absence records, rehabilitation information, and school incidents involving underage individuals. The threat actor demanded a ransom of 1.5 Bitcoin (valued at $168,000 at the time) to prevent leaking the stolen information but published it on the dark web under the name “Datacarry.” IMY’s investigation confirmed that the company failed to adequately check newly installed software and lacked automated, real-time monitoring mechanisms to detect intrusions and suspicious activity. The negligence constituted a violation of Article 32(1) of the GDPR. IMY also launched investigations into two municipalities and one region in connection with the attack, which are ongoing and may result in additional penalties. The company has since implemented enhanced security measures and monitoring systems.
(Source: Read full report)
BigCommerce alerts merchants of data breach linked to Ribon apps
Ecommerce platform BigCommerce alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. The cloud-based SaaS ecommerce platform confirmed the credential compromise on September 17 and immediately removed the apps to protect its customers. The hacker used the compromised credentials to access shopper data in BigCommerce environments between September 13 and September 17. Impacted shopper details include full names, email addresses, phone numbers, and shipping postal addresses. UK-based online spirits vendor Master of Malt was one of the affected customers that received notification. The attacker compromised credentials for Ribon and Ribon 1.5 applications operated by Be A Part Of, a Fastr company specialized in shopping experience optimization. BigCommerce confirmed that its systems or the BigCommerce platform itself were not breached, and that account passwords and payment card information are stored separately and were not exposed. The company uninstalled the application from affected stores to revoke the attacker’s access, notified merchants directly, and provided log data to support the developer’s investigation. Master of Malt reported the incident to the UK Information Commissioner’s Office (ICO) and noted that the breach may extend well beyond its own customers to hundreds of other stores.
(Source: Read full report)
Over 153 Million Driver’s Licenses Were Stolen by Hackers. Here’s What to Know
A major data breach involving identity-verification company IDScan.net has exposed potentially massive amounts of sensitive identity information. Hackers reportedly offered more than 153 million U.S. and Canadian driver’s license scans for sale on a dark-web marketplace, along with millions of other identity documents. The exposed information may include names, driver’s license numbers, photos, and document scans, creating risks of identity theft, fraud, and targeted phishing. IDScan confirmed that an unauthorized party may have accessed or copied customer information stored in its cloud, although 153 million is an externally reported figure and has not been confirmed as the number of affected individuals by IDScan. The FBI is investigating the incident, highlighting the security risks associated with storing large volumes of sensitive identity data with third-party verification providers.
(Source: Read full report)