9 October 2026

10 min read

Attackers publicise alleged ASOS breach in-app | Cyber Intelligence Briefing – 9 October 2026

October 2026
Cyber Intelligence Briefing

Top news stories this week

  1. A S.O.S. Attackers publicise alleged ASOS breach in-app.
  2. The moth files. Internal leaks expose Luna Moth’s victims, tactics and expansion plans.
  3. Open season. Suspected ShinyHunters leader detained as FBI expands investigation.
  4. Agent provocateur. Autonomous tooling linked to South Korean financial attacks.
  5. Lost in exfiltration. Several Japanese organisations disclose cyber breaches.
  6. Adding insult to injury. Cyber security company owner accused of profiting from ransomware victims.
  7. Ernst and exposed. EY breach exposes sensitive client financial data.

1. Attackers publicise alleged ASOS breach in-app

ASOS app users received an unusual notification titled “ASOS HACKED,” claiming attackers had breached an ASOS Snowflake instance and threatening to leak stolen data unless the company engaged with them via a linked Telegram channel. ASOS confirmed that the threat actor compromised their systems via a social engineering attack and accessed the names and contact details of their customers, but stated that payment card information and account passwords were not compromised.

So what?

The incident demonstrates that the attackers may use the communication tools of organisations to publicise an ongoing incident, which may also amplify reputational damage and customer concern.

[Researcher: Tlhalefo Dikolomela]  


2. Internal leaks expose Luna Moth’s victims, tactics and expansion plans

The prolific data extortion group Silent Ransom Group (SRG), better known as Luna Moth, has suffered a major breach of its own. Internal chat logs leaked this week provide an unprecedented view into the workings of an active cybercriminal organisation. The archive reportedly contains nearly 5,700 messages spanning more than a year of activity, from August 2025 to September 2026, revealing how the group recruits, targets, extorts and expands its operations.

So what?

The leak may expose previously undisclosed Luna Moth victims and details of past negotiations. Organisations with a history of Luna Moth activity should assess their potential exposure. Read S-RM's briefing note for further analysis and guidance.

[Researcher: Virginia Romero]  


3. Suspected ShinyHunters leader detained as FBI expands investigation

Jordanian authorities have detained the suspected leader of the ShinyHunters cybercrime collective, known online as "Rey", who is reportedly cooperating with the FBI in efforts to identify other members of the group. The FBI has also detained multiple individuals believed to be associated with ShinyHunters, however, authorities have not disclosed additional information regarding these arrests.

Separately, the FBI removed an Accenture contractor after determining that their failure to apply a required security patch contributed to the compromise of FBI systems.

So what?

The FBI breach has triggered a sustained law enforcement effort to identify and arrest those responsible. Whether the latest arrests and cooperation from alleged members will lead to the dismantling of ShinyHunters remains to be seen.

[Researcher:  Milda Petraityte ]


4. Autonomous tooling linked to South Korean financial attacks

South Korean financial regulators called for an emergency meeting to identify the common security weaknesses after a series of cyber incidents affected multiple Korean financial institutions. The breaches prompted President Lee Jae Myung to order a formal investigation and emergency sector-wide security measures. 

Separately, researchers investigating infrastructure linked to these attacks identified traces of ARTEX, an open-source autonomous penetration testing framework capable of automating reconnaissance, vulnerability discovery, attack-path planning and tooling execution. 

SO WHAT? 

Agentic tooling may increasingly augment established intrusion techniques. Rather than introducing entirely new attack methods, AI systems can help automate reconnaissance, vulnerability discovery, target selection and attack-path development, enabling attackers to operate at greater speed and scale.

[Researcher: Gabriella Nolan]


5. Several Japanese organisations disclose cyber breaches

A number of Japanese organisations disclosed cyber incidents this week. Media giant Nikkei reported two compromises involving employee email accounts, while information on up to 110,000 clients of Daiwa Securities Group may have been exposed following the compromise of an external vendor. Separately, semiconductor manufacturer Advantest disclosed that a February ransomware attack exposed personal data more than, six months after the incident occurred. Osaka Metropolitan University also cancelled classes after a suspected attack disrupted parts of its internal network, email and academic systems. 

So What?

Organisations should take the opportunity to review their response plan – which should include recovery testing and continuity plans for email, identity and other crucial services, contingencies for third party breaches – and follow-on disclosure.

[Researcher: Lester Lim]


6. Cybersecurity company owner accused of profiting from ransomware victims

The US Department of Justice (DoJ) has charged Zohar Pinhasi, owner of ransomware recovery company MonsterCloud, with two counts of wire fraud and one count of conspiracy to commit wire fraud. Prosecutors allege that he secretly paid ransomware operators for decryptors while claiming to use proprietary tools to recover clients’ data.
Pinhasi allegedly advised clients against paying ransoms while secretly making payments to hackers himself and charging clients significantly more for recovering their data.

SO WHAT? 

ansomware incidents often force organisations to make difficult decisions under significant time pressure. Organisations should ensure they understand how recovery efforts are being conducted and maintain clear communication with those managing the response, particularly around any payments made to attackers.

[Researcher: Asya Sonnichsen]


7. EY breach exposes sensitive client financial data

A breach at EY (Ernst & Young) exposed personal and financial information belonging to clients of Goldman Sachs’ wealth management division, hedge fund Man Group, and real estate developer Tishman Speyer. An unauthorized party accessed an EY platform and downloaded documents containing sensitive information like names, addresses, tax identification numbers, and financial information. EY has linked the incident to a vulnerability in Checkmarx software.

SO WHAT? 

The impact of third-paty breaches can continue to emerge long after the initial disclosure, particularly where professional services firms handle information for many clients. Organisations should track supplier incidents over time, reassess their own exposure as new victims are identified, and remember to treat sensitive data held by third parties is an extension of their own attack surface.

[Researcher: Steve Ross]

SUBSCRIBE TO RECEIVE OUR WEEKLY CYBER THREAT INTELLIGENCE BRIEFING VIA EMAIL

The S-RM Cyber Intelligence Briefing is a weekly round-up of the latest cyber security news, trends, and indicators, curated by our intelligence specialists.

To discuss this briefing or other industry developments, please reach out to one of our experts.

Editor

Share this post

Subscribe to our insights

Get industry news and expert insights straight to your inbox.