>
av.Amit VijayanCYBERSECURITY & RESEARCHav.Amit VijayanCYBERSECURITY & RESEARCHKnowledge libraryAbout MeLet’s connect
Back to the library

Cyber news

Daily Cyber Threat Brief — October 4, 2026: DTU Breach Exposes Data of Up to 200,000; ShinyHunters Member Detained in Jordan

Thumbnail for: Daily Cyber Threat Brief — October 4, 2026: DTU Breach Exposes Data of Up to 200,000; ShinyHunters Member Detained in Jordan

🗂️ CASE FILE — October 4, 2026

Lead story: The Technical University of Denmark (DTU) confirmed hackers accessed its DTUBasen identity and access management system with compromised credentials, potentially exposing data of up to 200,000 current and former users — including Danish CPR numbers, home addresses, and next-of-kin details. On October 4 the case escalated: DTU reported the incident to Datatilsynet (Denmark's data protection authority) and referred it to the National Special Crime Unit (NSK), turning the disclosure into a formal regulatory and criminal matter.

Also covered: ShinyHunters member "Rey" (Saif al-Din Khader) reportedly detained in Jordan and now aiding the FBI in locating co-conspirators · South Korea's Welcome Savings Bank confirms a breach affecting corporate clients (up to 2,200 records) · FortiMail zero-day (CVE-2026-104286) hits CISA's October 4 mitigation deadline · unverified 404Crew claim of a breach at Ukraine's MFA visa platform.

Sources: 6 linked at the end of this brief.

Today's top stories

The DTU breach dominated the weekend's incident news: a single IAM system with two decades of user data, Danish national-ID numbers in the mix, and now regulators and cybercrime police both involved. In parallel, the ShinyHunters saga took a sharp turn — one alleged member detained in Jordan is reportedly walking the FBI through his devices. Plus a South Korean bank breach, a CISA deadline expiring today, and an unverified threat-actor claim out of Ukraine.

DTU breach: up to 200,000 exposed as university reports to Datatilsynet and cybercrime police

The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data, per BleepingComputer (October 3). The attacker used compromised credentials to log into DTUBasen — the IAM system DTU uses to administer accounts, permissions, and user records — unlocking more than two decades of user data. DTU confirmed it cannot "determine precisely what information was downloaded or how many people have been affected." DTUBasen stores information for nearly 40,000 active users and around 160,000 former users; anyone who has been an employee, student, guest, or external partner of DTU since 2003 may be affected.

For current users, potentially exposed data includes Danish civil registration numbers (CPR), full names, home addresses, and profile pictures, plus work email addresses, job titles, and office locations. The dataset also held names, relationships, and telephone numbers of users' next of kin. DTU warns criminals could use the CPR numbers for identity fraud and to make phishing attacks more convincing. Notification is going out through e-Boks, Denmark's official digital mailbox, though not all former students whose CPR numbers are held will be notified directly.

On October 4, DTU handed the case to Datatilsynet, Denmark's data protection authority, and separately referred it to investigative authorities — The Copenhagen Post reported contact with Denmark's National Special Crime Unit (NSK), per tech-insider.org. A regulator and a national crime unit working one incident in parallel moves the story from breach disclosure to formal regulatory and criminal proceedings — and under GDPR, the regulatory leg can carry eight-figure exposure. "This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected," said University Director Bjarke Bak Christensen.

🔍 Investigation notes — defender takeaway (click to expand)

The attack path was mundane: compromised credentials against an IAM system — the skeleton key to two decades of identity records. This is why IAM systems deserve tier-0 treatment: phishing-resistant MFA, anomaly detection on privileged logins, and full session logging. DTU's honesty about not knowing the exact scope is notable and correct — understating blast radius is how organizations lose trust twice. For defenders: any org with long-lived identity stores should assume an IAM breach exposes "everything since inception," and notification plans should account for users who left years ago.

ShinyHunters' "Rey" detained in Jordan, reportedly aiding FBI hunt for co-conspirators

A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group, per BleepingComputer (October 3), citing Reuters. Jordanian authorities detained Saif al-Din Khader — identified by sources as the person behind the Rey alias — with two sources saying he was taken into custody on Tuesday. One source said Khader is walking law enforcement through his electronic devices and digital communications to help identify alleged co-conspirators. "His cooperation is critical to ongoing efforts to arrest these hackers," a source told Reuters.

The detention lands amid an FBI crackdown on ShinyHunters following the group's claimed cyberattack on the bureau itself. In September, ShinyHunters told BleepingComputer it breached FBI systems using an alleged Oracle PeopleSoft zero-day, then moved laterally into FBI-managed AWS GovCloud systems, claiming 2TB to 3TB of stolen data including information on current and former FBI employees, job applicants, and medical and psychiatric records. BleepingComputer has not independently verified the alleged zero-day, lateral movement, or data volume, and the FBI confirmed only that it was investigating claims of unauthorized activity. On September 15, Dutch police arrested 24-year-old Pepijn van der Stap ("Umbreon") in Amsterdam as part of the same investigation; neither the FBI nor Jordanian authorities have publicly confirmed Khader's detention.

🔍 Investigation notes — defender takeaway (click to expand)

Cooperating insiders are how these networks unravel — devices and message histories map aliases to real people far faster than infrastructure forensics. The operational lesson from the group's alleged success: one exploited enterprise application (the claimed PeopleSoft flaw) allegedly opened a path to cloud infrastructure. Patching perimeter apps protects the blast radius you can't see yet. Note the reporting caveats: Khader's role and detention status rest on unnamed sources, and the FBI breach claims remain unverified — treat the 2–3TB figure as a threat-actor claim, not a confirmed theft.

Welcome Savings Bank confirms breach of corporate client data in South Korea

Welcome Savings Bank has confirmed a data breach affecting its corporate clients, the latest in a string of hacking incidents hitting South Korean financial firms, per Aju Press and the Seoul Economic Daily (October 4). The bank discovered the breach during an internal security review on October 3 and reported it to financial regulators. Exposed information is believed to include corporate names, contact persons' names, email addresses, and phone numbers, with up to 2,200 records identified so far. The bank has launched an investigation into how the intrusion occurred and the true scale of leaked data.

🔍 Investigation notes — defender takeaway (click to expand)

Contact-level corporate data is prime fuel for targeted business-email compromise and vendor-impersonation campaigns against the bank's clients — the notification to regulators suggests South Korea's financial authorities are treating this as part of a sector-wide wave, not an isolated incident. Firms doing business with Welcome Savings Bank should treat unexpected outreach referencing the relationship as suspect until the bank's investigation closes.

CISA deadline day: FortiMail zero-day mitigation due today for federal agencies

CISA added the actively exploited FortiMail flaw CVE-2026-104286 to its Known Exploited Vulnerabilities catalog with a mitigation and forensic-triage deadline of October 4, per BleepingComputer (October 1). Fortinet warned the critical flaw was being exploited in zero-day attacks to execute unauthorized code and commands on vulnerable devices; the company has not disclosed when exploitation began, how many systems were compromised, or who is behind it. Fortinet says it is coordinating with government agencies, including CISA, on the advisory. Any FortiMail deployment still unpatched after today should be treated as potentially compromised and scoped accordingly.

Unverified claims desk: 404Crew alleges Ukraine MFA visa platform breach

A threat actor group calling itself 404Crew Cyber Team claims to have compromised a visa application platform associated with Ukraine's Ministry of Foreign Affairs, publicized by Dark Web Intelligence on October 4 via undercodenews. The underground post reportedly uses Ukrainian MFA branding and warns of further material. The claims have not been independently verified — no passport or visa applicant data samples were included, and there is no confirmed evidence the MFA's infrastructure was breached. Filed here as an unverified claim, not a confirmed incident.

Incident timeline — October 2 to October 4, 2026

DateEventStatus
Sep 15Dutch police arrest 24-year-old "Umbreon" (Pepijn van der Stap) in Amsterdam in ShinyHunters investigationConfirmed arrest
Sep 29Jordanian authorities reportedly detain ShinyHunters' "Rey" (Saif al-Din Khader), per Reuters sourcesReported, not publicly confirmed
Oct 1Fortinet warns of actively exploited FortiMail zero-day (CVE-2026-104286); CISA adds it to KEVConfirmed advisory
Oct 2DTU discloses breach of DTUBasen IAM system; up to 200,000 users may be affectedConfirmed by DTU
Oct 3Welcome Savings Bank discovers corporate-client data breach during internal review; reports to regulatorsConfirmed by bank
Oct 4DTU reports incident to Datatilsynet and refers to NSK cybercrime policeReported (tech-insider.org / The Copenhagen Post)
Oct 4CISA KEV deadline: federal agencies must complete FortiMail forensic triage and mitigationDeadline today
Oct 4404Crew claims breach of Ukraine MFA visa platform; 404Crew also claims Elbaite crypto exchange breachUnverified claims

Source links

From the HackInvasion archive

This sample preserves the article’s original text and publication date, restyled for Amit’s personal website. Older material may describe historical tools or techniques.

Read the original article on Blogger

Keep exploring.

All articles