🗂️ CASE FILE — October 4, 2026
Lead story: The Technical University of Denmark (DTU) confirmed hackers accessed its DTUBasen identity and access management system with compromised credentials, potentially exposing data of up to 200,000 current and former users — including Danish CPR numbers, home addresses, and next-of-kin details. On October 4 the case escalated: DTU reported the incident to Datatilsynet (Denmark's data protection authority) and referred it to the National Special Crime Unit (NSK), turning the disclosure into a formal regulatory and criminal matter.
Also covered: ShinyHunters member "Rey" (Saif al-Din Khader) reportedly detained in Jordan and now aiding the FBI in locating co-conspirators · South Korea's Welcome Savings Bank confirms a breach affecting corporate clients (up to 2,200 records) · FortiMail zero-day (CVE-2026-104286) hits CISA's October 4 mitigation deadline · unverified 404Crew claim of a breach at Ukraine's MFA visa platform.
Sources: 6 linked at the end of this brief.
Today's top stories
The DTU breach dominated the weekend's incident news: a single IAM system with two decades of user data, Danish national-ID numbers in the mix, and now regulators and cybercrime police both involved. In parallel, the ShinyHunters saga took a sharp turn — one alleged member detained in Jordan is reportedly walking the FBI through his devices. Plus a South Korean bank breach, a CISA deadline expiring today, and an unverified threat-actor claim out of Ukraine.
DTU breach: up to 200,000 exposed as university reports to Datatilsynet and cybercrime police
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data, per BleepingComputer (October 3). The attacker used compromised credentials to log into DTUBasen — the IAM system DTU uses to administer accounts, permissions, and user records — unlocking more than two decades of user data. DTU confirmed it cannot "determine precisely what information was downloaded or how many people have been affected." DTUBasen stores information for nearly 40,000 active users and around 160,000 former users; anyone who has been an employee, student, guest, or external partner of DTU since 2003 may be affected.
For current users, potentially exposed data includes Danish civil registration numbers (CPR), full names, home addresses, and profile pictures, plus work email addresses, job titles, and office locations. The dataset also held names, relationships, and telephone numbers of users' next of kin. DTU warns criminals could use the CPR numbers for identity fraud and to make phishing attacks more convincing. Notification is going out through e-Boks, Denmark's official digital mailbox, though not all former students whose CPR numbers are held will be notified directly.
On October 4, DTU handed the case to Datatilsynet, Denmark's data protection authority, and separately referred it to investigative authorities — The Copenhagen Post reported contact with Denmark's National Special Crime Unit (NSK), per tech-insider.org. A regulator and a national crime unit working one incident in parallel moves the story from breach disclosure to formal regulatory and criminal proceedings — and under GDPR, the regulatory leg can carry eight-figure exposure. "This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected," said University Director Bjarke Bak Christensen.
🔍 Investigation notes — defender takeaway (click to expand)
The attack path was mundane: compromised credentials against an IAM system — the skeleton key to two decades of identity records. This is why IAM systems deserve tier-0 treatment: phishing-resistant MFA, anomaly detection on privileged logins, and full session logging. DTU's honesty about not knowing the exact scope is notable and correct — understating blast radius is how organizations lose trust twice. For defenders: any org with long-lived identity stores should assume an IAM breach exposes "everything since inception," and notification plans should account for users who left years ago.
ShinyHunters' "Rey" detained in Jordan, reportedly aiding FBI hunt for co-conspirators
A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group, per BleepingComputer (October 3), citing Reuters. Jordanian authorities detained Saif al-Din Khader — identified by sources as the person behind the Rey alias — with two sources saying he was taken into custody on Tuesday. One source said Khader is walking law enforcement through his electronic devices and digital communications to help identify alleged co-conspirators. "His cooperation is critical to ongoing efforts to arrest these hackers," a source told Reuters.
The detention lands amid an FBI crackdown on ShinyHunters following the group's claimed cyberattack on the bureau itself. In September, ShinyHunters told BleepingComputer it breached FBI systems using an alleged Oracle PeopleSoft zero-day, then moved laterally into FBI-managed AWS GovCloud systems, claiming 2TB to 3TB of stolen data including information on current and former FBI employees, job applicants, and medical and psychiatric records. BleepingComputer has not independently verified the alleged zero-day, lateral movement, or data volume, and the FBI confirmed only that it was investigating claims of unauthorized activity. On September 15, Dutch police arrested 24-year-old Pepijn van der Stap ("Umbreon") in Amsterdam as part of the same investigation; neither the FBI nor Jordanian authorities have publicly confirmed Khader's detention.
🔍 Investigation notes — defender takeaway (click to expand)
Cooperating insiders are how these networks unravel — devices and message histories map aliases to real people far faster than infrastructure forensics. The operational lesson from the group's alleged success: one exploited enterprise application (the claimed PeopleSoft flaw) allegedly opened a path to cloud infrastructure. Patching perimeter apps protects the blast radius you can't see yet. Note the reporting caveats: Khader's role and detention status rest on unnamed sources, and the FBI breach claims remain unverified — treat the 2–3TB figure as a threat-actor claim, not a confirmed theft.
Welcome Savings Bank confirms breach of corporate client data in South Korea
Welcome Savings Bank has confirmed a data breach affecting its corporate clients, the latest in a string of hacking incidents hitting South Korean financial firms, per Aju Press and the Seoul Economic Daily (October 4). The bank discovered the breach during an internal security review on October 3 and reported it to financial regulators. Exposed information is believed to include corporate names, contact persons' names, email addresses, and phone numbers, with up to 2,200 records identified so far. The bank has launched an investigation into how the intrusion occurred and the true scale of leaked data.
🔍 Investigation notes — defender takeaway (click to expand)
Contact-level corporate data is prime fuel for targeted business-email compromise and vendor-impersonation campaigns against the bank's clients — the notification to regulators suggests South Korea's financial authorities are treating this as part of a sector-wide wave, not an isolated incident. Firms doing business with Welcome Savings Bank should treat unexpected outreach referencing the relationship as suspect until the bank's investigation closes.
CISA deadline day: FortiMail zero-day mitigation due today for federal agencies
CISA added the actively exploited FortiMail flaw CVE-2026-104286 to its Known Exploited Vulnerabilities catalog with a mitigation and forensic-triage deadline of October 4, per BleepingComputer (October 1). Fortinet warned the critical flaw was being exploited in zero-day attacks to execute unauthorized code and commands on vulnerable devices; the company has not disclosed when exploitation began, how many systems were compromised, or who is behind it. Fortinet says it is coordinating with government agencies, including CISA, on the advisory. Any FortiMail deployment still unpatched after today should be treated as potentially compromised and scoped accordingly.
Unverified claims desk: 404Crew alleges Ukraine MFA visa platform breach
A threat actor group calling itself 404Crew Cyber Team claims to have compromised a visa application platform associated with Ukraine's Ministry of Foreign Affairs, publicized by Dark Web Intelligence on October 4 via undercodenews. The underground post reportedly uses Ukrainian MFA branding and warns of further material. The claims have not been independently verified — no passport or visa applicant data samples were included, and there is no confirmed evidence the MFA's infrastructure was breached. Filed here as an unverified claim, not a confirmed incident.
Incident timeline — October 2 to October 4, 2026
| Date | Event | Status |
|---|---|---|
| Sep 15 | Dutch police arrest 24-year-old "Umbreon" (Pepijn van der Stap) in Amsterdam in ShinyHunters investigation | Confirmed arrest |
| Sep 29 | Jordanian authorities reportedly detain ShinyHunters' "Rey" (Saif al-Din Khader), per Reuters sources | Reported, not publicly confirmed |
| Oct 1 | Fortinet warns of actively exploited FortiMail zero-day (CVE-2026-104286); CISA adds it to KEV | Confirmed advisory |
| Oct 2 | DTU discloses breach of DTUBasen IAM system; up to 200,000 users may be affected | Confirmed by DTU |
| Oct 3 | Welcome Savings Bank discovers corporate-client data breach during internal review; reports to regulators | Confirmed by bank |
| Oct 4 | DTU reports incident to Datatilsynet and refers to NSK cybercrime police | Reported (tech-insider.org / The Copenhagen Post) |
| Oct 4 | CISA KEV deadline: federal agencies must complete FortiMail forensic triage and mitigation | Deadline today |
| Oct 4 | 404Crew claims breach of Ukraine MFA visa platform; 404Crew also claims Elbaite crypto exchange breach | Unverified claims |
Source links
- BleepingComputer: Danish university DTU breach exposes data of up to 200,000 people
- Tech Insider: DTU breach fallout — Datatilsynet, NSK probe open (citing The Copenhagen Post)
- BleepingComputer: ShinyHunters hacker reportedly detained in Jordan, aiding FBI
- Aju Press: Welcome Savings Bank confirms data breach affecting corporate clients
- BleepingComputer: Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
- Undercode News: 404Crew claims Ukraine MFA visa platform breach (unverified)
This sample preserves the article’s original text and publication date, restyled for Amit’s personal website. Older material may describe historical tools or techniques.
Read the original article on Blogger