The week of 21 to 27 September 2026 was defined by attackers monetizing access faster than victims could detect it. Bitget lost 351.6 million dollars to a suspected North Korean crew that spoofed its own wallet approvals, ShinyHunters claimed a breach of FBI job applicant data through an unpatched Oracle PeopleSoft zero-day, Gyazo confirmed 23.6 million user records and 490 million image metadata records were stolen through a server flaw, a compromise at broker DriveWealth exposed historical Revolut customer data through a former third-party integration, and a Kosovo national pleaded guilty to running the Rydox cybercrime marketplace that sold stolen identities in over 7,600 transactions. The shared mechanism across four of the five incidents was a trusted system, an API, a vendor integration, an employment portal, being turned against the organization that trusted it, rather than a perimeter being smashed down.
1. Bitget crypto exchange loses $351.6 million in suspected North Korean hot wallet attack
Overview: Bitget, a global cryptocurrency exchange, detected unauthorized transfers from its hot and warm wallets at 18:31 UTC on 24 September 2026, and disclosed the incident the same day through its own statement and blockchain analysis firm TRM Labs.
Impact: Attackers moved 351.6 million dollars in digital assets across seven blockchains, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, and Base. Bitget’s cold wallets were unaffected, and the exchange said its 464 million dollar User Protection Fund covers the loss in full.
Details: According to Bitget’s CEO, attackers compromised a backend system connected to the exchange’s wallet infrastructure and spoofed transaction approval data, authorizing transfers without ever obtaining the exchange’s private keys. TRM Labs’ analysis found on-chain overlaps between the laundering wallets and infrastructure used in prior North Korea-linked heists against Bybit and AFX Bridge, and identified the same rapid-splitting, round-amount laundering pattern TRM attributes to the Lazarus-linked TraderTraitor operation. Bitget’s CEO separately cited IP addresses matching VPN services associated with North Korean hacking groups, and called North Korean involvement "very likely" rather than confirmed.
Remediation guidance: Segment wallet approval infrastructure from customer-facing systems so a spoofed approval cannot authorize a transfer without a second, out-of-band verification. Rotate and re-scope any backend service credentials with wallet-signing authority on a fixed cadence rather than only after an incident. Maintain a funded, tested customer protection reserve sized to a realistic worst-case loss, not an average one.
2. ShinyHunters claims FBI breach through unpatched Oracle PeopleSoft zero-day
Overview: The extortion group ShinyHunters claimed on 22 September 2026 to have breached FBI systems by exploiting an unpatched Oracle PeopleSoft zero-day, defacing the FBIjobs.gov site with its own logo and a message declaring the site "seized."
Impact: ShinyHunters claims to have exfiltrated 2 to 3 terabytes of data covering current and former FBI employees and job applicants. The FBI confirmed awareness of unauthorized activity affecting FBIjobs.gov and stated it is investigating, but has not confirmed the scope of any breach or data theft. Independent outlet 404 Media received roughly 5,000 purported employee records from the group and verified some of the information as accurate.
Details: No CVE has been assigned to the PeopleSoft flaw ShinyHunters describes, and Oracle has not issued a corresponding advisory as of this report. The group says the zero-day remains unpatched and that it is actively using it against other Fortune 500 and education-sector targets, and states the attack was retaliation for a May 2026 FBI FLASH report on the group’s activities. Because the underlying vulnerability is unconfirmed and unpatched, this entry should be read as a claim under active investigation rather than a settled fact, consistent with the partial and defaced evidence made public so far.
Remediation guidance: Treat any employee-facing PeopleSoft or similar HR and applicant-tracking portal as a discrete, internet-facing asset requiring its own exposure review, not an extension of the internal network’s trust boundary. Monitor for defacement and unauthorized content changes on public-facing recruitment and HR portals as a leading indicator, since these are lower-priority monitoring targets than production systems. Prepare a pre-approved communications and forensics plan for extortion-group claims before one lands, so verification does not compete with panic.
3. Gyazo confirms 23.6 million user records and 490 million image metadata records stolen
Overview: Image-hosting service Gyazo, operated by Helpfeel, confirmed that a third party exploited a server vulnerability to access its database, with the intrusion occurring around 11 September 2026 and public disclosure following in the week of 21 to 27 September.
Impact: The breach exposed 23.62 million user records and 490 million image metadata records. User data varied by account and could include names or nicknames, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google SSO emails, and subscription and billing details. Metadata exposure included image IDs, upload IPs, User-Agent strings, EXIF location data, and OCR-extracted text from images.
Details: Gyazo stated its investigation "confirmed that the third party had accessed Gyazo’s database and that user information and metadata… had been disclosed without authorization." The company took the platform offline for maintenance, engaged external forensic experts, and contacted authorities. Helpfeel said it found no evidence of data deletion or compromise affecting its other services, meaning the exposure appears contained to Gyazo’s own database rather than the broader Helpfeel environment.
Remediation guidance: Force a password reset for all affected accounts and invalidate existing session and OAuth tokens rather than relying on users to act voluntarily. Audit what image metadata a hosting platform retains by default, including EXIF location and OCR text, since that retention decision is what turned an image breach into a location and content exposure. Review third-party SSO integrations (Google, X) for any token or linkage data a breach on your side could expose on theirs.
4. DriveWealth breach exposes historical Revolut customer data through former broker integration
Overview: US brokerage DriveWealth, which formerly provided investment services to Revolut before customers migrated off the platform between December 2023 and June 2025, confirmed on 25 September 2026 that attackers used social engineering to gain unauthorized access to its systems between 4 and 5 September 2026.
Impact: The breach exposed historical personal information tied to accounts customers previously held directly with DriveWealth, including names, email addresses, phone numbers, postal addresses, employment information, country of citizenship, age, gender, and partial DriveWealth account numbers. Passwords, payment information, and bank account numbers were not exposed. Neither company disclosed the number of affected customers.
Details: This is a distinct incident from a separate 14 September 2026 Revolut breach involving fraudulent government-style data requests; the two involved different attackers and different access routes. Revolut confirmed its own systems and infrastructure were not compromised and that customer funds and investments remained safe, characterizing the exposure as originating entirely within DriveWealth’s environment from a legacy integration that had already been wound down.
Remediation guidance: Maintain an inventory of former third-party integrations and the data they retained after an integration ends, not just active ones, since a wound-down vendor relationship does not retroactively delete historical exposure. Require former data-sharing partners to confirm deletion or provide an attestation of ongoing protections for legacy records. Extend social engineering awareness training to include vendor and partner-facing staff who may hold data for customers they never directly served.
5. Kosovo national pleads guilty to running Rydox cybercrime marketplace
Overview: The US Department of Justice announced on 24 September 2026 that Ardit Kutleshi, a 28-year-old Kosovo national, pleaded guilty to aggravated identity theft and money laundering conspiracy for operating the Rydox cybercrime marketplace.
Impact: According to the DOJ, Rydox generated at least 232,000 dollars in revenue across more than 7,600 transactions involving stolen personally identifiable information, compromised access devices, and cybercrime tools sold to other criminals. The marketplace trafficked in personal data stolen from victims located in the United States. Kutleshi faces up to 20 years in prison on the money laundering count plus a mandatory minimum of 2 years for aggravated identity theft, with sentencing set for 9 February 2027.
Details: Kutleshi’s brother, Jetmir Kutleshi, previously pleaded guilty as a co-conspirator in the same marketplace and was sentenced before being deported to Kosovo in December 2025. Rydox functioned as a criminal supply chain in its own right, selling the raw material, stolen identities and access, that other threat actors used to commit further fraud and intrusion. Full charging details are in the Department of Justice press release.
Remediation guidance: Treat marketplace takedowns and guilty pleas as a signal to check whether your organization’s data has surfaced in known marketplace inventories, not just a headline to note. Monitor for credential and PII exposure using threat intelligence feeds that track dark web marketplaces rather than assuming a takedown retroactively protects prior victims. Reinforce identity verification steps for account recovery and support processes, since marketplace-sourced PII is most commonly weaponized through social engineering and account takeover.
Related reading
- Weekly Cybersecurity Intelligence Report: Cyber Threats and Breaches, 07 Sep to 13 Sep 2026: last edition’s credential-abuse pattern, visible again this week in the DriveWealth and Rydox items.
- The Jaguar Land Rover cyberattack: an earlier example of how a single compromised system cascades into extended operational impact, the same dynamic behind this week’s Bitget wallet-approval spoofing.
- The Great AI Divide: the widening gap between attacker speed and defender testing cadence that this week’s incidents illustrate at both the criminal-marketplace and nation-state level.
How FireCompass helps
Four of this week’s five incidents traced back to a trusted integration point, a wallet-approval backend, an HR portal, a former broker connection, an identity marketplace, being exploited rather than a perimeter being breached outright. That is exactly the class of exposure that goes untested in an annual pentest cycle, because annual testing typically covers about 20 percent of an organization’s actual surface in a single snapshot, while the vendors, portals, and integrations that make up the rest keep changing between tests. FireCompass’s AI agents run continuously against internet-facing web applications and APIs, validating exploitability with proof-of-concept evidence rather than flagging theoretical weaknesses, holding a false positive rate under 2 percent against the 40 to 70 percent typical of scanners. Continuous validation catches the integration that was decommissioned improperly or the API endpoint added last sprint before an attacker finds it first.
Frequently asked questions
What was the biggest cyberattack this week (21 to 27 Sep 2026)?
The Bitget cryptocurrency exchange hack was the most financially significant, with attackers stealing 351.6 million dollars across seven blockchains on 24 September 2026 by spoofing wallet transaction approvals. Bitget’s CEO called suspected North Korean involvement "very likely" based on on-chain and infrastructure overlaps with prior attacks.
Did the FBI actually get breached by ShinyHunters?
The FBI has confirmed only that it is investigating unauthorized activity affecting its FBIjobs.gov site as of 22 September 2026, not that a breach or data theft occurred. ShinyHunters claims to have stolen 2 to 3 terabytes of employee and applicant data through an unpatched Oracle PeopleSoft zero-day, but no CVE has been assigned and the claim remains unconfirmed.
How many records were exposed in the Gyazo breach?
Gyazo confirmed 23.62 million user records and 490 million image metadata records were accessed without authorization through a server vulnerability, with the underlying intrusion occurring around 11 September 2026 and disclosure following in the week of 21 to 27 September.
Is the DriveWealth breach the same incident as the earlier Revolut data exposure?
No. DriveWealth’s breach, disclosed 25 September 2026 and involving social engineering against its own systems between 4 and 5 September, is a separate incident from a 14 September 2026 Revolut breach involving fraudulent government-style data requests. Revolut said its own systems were not compromised in either case.
What happened with the Rydox marketplace case?
A Kosovo national, Ardit Kutleshi, pleaded guilty on 24 September 2026 to running the Rydox cybercrime marketplace, which generated at least 232,000 dollars across more than 7,600 transactions selling stolen identities and cybercrime tools. He faces up to 20 years in prison plus a mandatory 2-year minimum, with sentencing set for 9 February 2027.
What is the common pattern across this week’s incidents?
Four of five incidents involved a trusted system, backend, third-party integration, employment portal, or criminal marketplace, being turned against the organization or individuals that relied on it, rather than a direct perimeter breach. Continuous exposure validation across externally reachable systems and integrations is the practical defense against this pattern, since it surfaces the weak trust relationship before an attacker does.
