Content 

01. News Bites
  • ASOS confirms data breach after hackers send unauthorised app alerts

  • EY breach exposes data linked to Goldman Sachs and Man Group

  • Nikkei email breaches expose personal data and trigger 9,000 phishing messages

  • Danish register breach exposes personal data of 8.8 million people

  • AI tools linked to cyberattacks targeting South Korean banks

  • Canadian cybersecurity budget confidence falls despite increased spending

02. Conclusion

Quick News Bites

ASOS confirms data breach after hackers send unauthorised app alerts

ASOS has confirmed a data breach after attackers accessed third-party customer communications platforms and sent unauthorised push notifications through its mobile app.

The UK fashion retailer said basic personal information, including names and contact details, may have been exposed. It does not believe payment-card details or account passwords were affected.

The notifications claimed that ASOS’s Snowflake environment had been compromised and threatened to leak stolen data unless the company engaged with the attackers. Customers were directed to a Telegram channel operated by a group calling itself “Xuanye”.

ASOS has not confirmed the Snowflake claim, and the attackers have not provided evidence supporting it. The number of customers potentially affected remains undisclosed.

An in-app notice advises customers to disregard the alert and avoid clicking or engaging with its external link.

The incident highlights how compromised communications platforms can allow attackers to reach customers directly, using trusted applications to distribute threatening messages.

EY breach exposes data linked to Goldman Sachs and Man Group

EY has warned that a breach of a platform supporting its tax services exposed personal and financial information belonging to individuals linked to Goldman Sachs and Man Group.

An unauthorised third party accessed the platform between 28 March and 12 April 2026, downloading documents connected to multiple EY clients. Exposed information included names, addresses, tax identification numbers, email addresses and financial details.

EY detected unusual activity on 23 April and engaged an independent cybersecurity firm to investigate. Sensitive tax documents had been attached to support tickets within the affected platform.

Goldman Sachs and Man Group confirmed that their own systems were not compromised. Goldman Sachs also said client assets remained safe.

The number of affected individuals associated with either firm has not been disclosed. EY is offering credit monitoring and identity protection services.

The incident highlights the exposure created when sensitive client information is retained in third-party support systems.

Nikkei email breaches expose personal data and trigger 9,000 phishing messages

Japanese publishing group Nikkei has disclosed two employee email account breaches, including one used to send 9,000 phishing messages to staff and interviewees.

The first incident involved unauthorised access to a Google Workspace account in late July, potentially exposing the names and email addresses of 1,646 employees and business partners. Nikkei said reader and interviewee information was not included in the affected data.

The company changed the account’s password after Google alerted it to the breach in early August.

In September, attackers accessed a separate Microsoft 365 account and used it to distribute emails containing malicious links on 30 September. Nikkei reset passwords, contacted recipients and asked them to delete the messages. It said no further unauthorised logins had been confirmed.

The company has not identified the attackers or established whether the incidents are connected.

Nikkei warned affected individuals to remain alert for further phishing attempts impersonating the company or its subsidiaries.

Danish register breach exposes personal data of 8.8 million people

Denmark’s government has confirmed that attackers accessed personal information belonging to 8.8 million people through the country’s Central Person Register (CPR).

The exposed data included names, addresses and CPR identification numbers. Attackers exploited a Danish company’s legitimate access to the register, highlighting the risks associated with third-party connections to sensitive government systems.

Although Denmark has around six million residents, the register also holds records relating to people who have emigrated or died. Authorities said protected names and addresses were not accessed.

The government disclosed the incident on 5 October, with investigators still establishing its full extent and identifying those responsible. Police are investigating, and the breach has been reported to Denmark’s data protection regulator.

Additional safeguards have been introduced. Authorities warned those affected to remain alert for phishing emails, texts and calls impersonating banks or public bodies, stressing that knowledge of personal details does not prove a request is legitimate.

AI tools linked to cyberattacks targeting South Korean banks

CrowdStrike has linked recent cyberattacks against South Korean financial institutions to a suspected attacker using AI tools, including the ARTEX penetration testing agent and Anthropic’s Claude Code.

At least nine banks have disclosed attacks or been reported as targets since late September. Shinhan Bank said around 25,000 customers’ personal information was compromised, while KB Kookmin Bank reported data leaks affecting 119 customers.

CrowdStrike assessed with moderate confidence that the attacker was likely Chinese-speaking and financially motivated. Its analysis identified sessions seeking information about selling stolen Korean data and locating Telegram groups used for data sales.

The firm also uncovered personal details suggesting a possible suspect in China, although the individual’s identity and responsibility remain unconfirmed.

South Korean police have launched an investigation, and President Lee Jae Myung has called for robust response measures.

The campaign raises concerns about attackers using AI agents to support intrusions and accelerate malicious activity against banks.

Canadian cybersecurity budget confidence falls despite increased spending

Canadian organisations are becoming less confident that their cybersecurity budgets can keep pace with threats, despite most increasing spending over the past year.

A Canadian Internet Registration Authority survey of 503 cybersecurity decision-makers found that 76% represented organisations that had raised their security budgets. However, only 67% considered their funding sufficient, down from 74% last year.

Four in ten organisations experienced a cyberattack during the past year. Among those affected by ransomware, 75% said they paid the ransom, typically handing over at least C$25,000.

Preparedness measures were widespread: 87% had an incident response plan and 82% held cybersecurity insurance. Meanwhile, more than eight in ten respondents expressed concern about AI-based threats, as two-thirds reported integrating AI into their operations.

Data sovereignty also influenced purchasing decisions, with nearly seven in ten prioritising it over price when selecting cybersecurity vendors.

The findings reflect growing pressure on security teams as threats outpace resources.

Closing Summary

If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively Get in touch to find out how you can protect your organisation. 

Disclaimer

The Threat Intel Roundup was prepared by Integrity360 summarising threat news as we observe it, current at the date of publishing. It should not be considered to be legal, consulting or any other professional advice. Any recommendations should be considered in the context of your own organisation. Integrity360 does not take any political stance in the information that we share. Moreover, the opinions expressed may not necessarily be the views of Integrity360.