Week 40

SecureFact – October 5, 2026

Major cybersecurity incidents impacted universities, education technology, government, defense, software development, and transportation organizations, exposing sensitive personal, employee, military, and credential data while highlighting risks from compromised systems, software vulnerabilities, exposed secrets, and ransomware attacks.

Danish University DTU Breach Exposes Data of Up to 200,000 People

The Technical University of Denmark (DTU) disclosed a major data breach affecting up to 200,000 users after hackers accessed its identity and access management (IAM) system using compromised credentials. The attackers downloaded a large amount of data spanning more than two decades of user records. Exposed information for current users includes Danish civil registration numbers (CPR), full names, home addresses, profile pictures, work email addresses, job titles, office locations, and next of kin names, relationships, and telephone numbers. The university confirmed it cannot precisely determine what information was downloaded or the exact number of affected individuals. DTU noted that former users’ home addresses, profile pictures, and next of kin information are automatically deleted after six months. The organization warned that cybercriminals could use exposed CPR numbers and personal data for identity fraud and phishing attacks. DTU is notifying affected individuals through e-Boks and recommending password changes, credit monitoring, and placing credit alerts on affected CPR numbers.

(Source: Read full report)

Frontline Education Breach Exposes School District Employee Data

Frontline Education, an edtech company providing administration and workforce management software to school districts, disclosed a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems. The company identified the vulnerability on August 14, 2026, and promptly investigated with assistance from an independent cybersecurity firm, remediated the vulnerability, and engaged law enforcement. Exposed employee information includes Social Security numbers, email addresses, and physical addresses. At least one school district reported 1,210 employees were impacted by the breach. Frontline is handling notifications to affected individuals on behalf of impacted school districts unless districts opt out by October 16. Affected adults are being offered two years of free credit monitoring and identity theft protection through TransUnion, while minors receive cyber monitoring services. The company is covering costs associated with individual notifications and identity protection services, as well as required notifications to state attorneys general.

(Source: Read full report)

Pentagon data breach exposes Social Security numbers, personal info of 2.76M US military, civilian personnel

A breach of the Pentagon’s Defense Manpower Data Center (DMDC) exposed sensitive personal information belonging to 2.76 million living U.S. military and civilian personnel, along with records of about 294,000 deceased individuals. Unauthorized users accessed unencrypted files containing Social Security numbers and employment or military information between October 2025 and July 2026. The vulnerability was discovered on July 16 in a file-sharing system, after which the Pentagon patched the issue and notified affected individuals. The Pentagon says there is currently no evidence that the exposed information has been misused, but the incident highlights the risks of storing sensitive personnel data without adequate protection

(Source: Read full report)

Over 543,000 valid credentials exposed in public GitHub repositories

A security analysis by Truffle Security found that more than 543,000 valid credentials were exposed in public GitHub repositories, despite GitHub’s security measures designed to prevent secret leaks. The research, which analyzed 224 million repositories and more than 58 billion files, found that exposed credentials remained publicly accessible for a median of 784 days, with some dating back to 2009. While GitHub’s Push Protection reduced exposure of the secret types it covers, 51.8% of the active credentials fell into categories that its default protection does not block, including database connection strings and Google API keys. The findings highlight the importance of regularly rotating and expiring credentials, scanning repository history, and removing secrets from code to reduce the risk of unauthorized access.

(Source: Read full report)

Japan’s Keio Confirms Ransomware Attack Disrupted Business Systems

Keio Corporation, a major private railway operator in Japan with 85 km of track, 69 stations, and 25 hotels, confirmed a ransomware attack over the weekend that disrupted some of its business systems. Following a system failure in the early hours of September 26, 2026, the company confirmed the ransomware attack and shut down its network to prevent additional damage. The incident appears to have affected only the hospitality side of Keio’s business, not train operations. Local media reported that the cyberattack disrupted the firm’s payment systems. Keio reported the incident to police and is conducting an investigation into the attack’s route and damage with cooperation from external experts. The company is investigating the extent of the impact and whether attackers accessed any customer or business partner information. At the time of reporting, no ransomware group had claimed responsibility for the attack. Tokyo Metro, another Japanese railway operator, also disclosed a separate cyber incident where attackers gained unauthorized access and accessed 59,000 member email addresses, though it remains unclear if both organizations were targeted in a coordinated campaign.

(Source: Read full report)

Stay updated with SecureFact™

Get weekly cybersecurity insights delivered to your feed.

Subscribe