9 min read

this week in security — september 13 2026 edition

Berlin responding to data breach ahead of elections, Apple to roll out 'always-listening' features, experts stress-test GPS jamming attacks, Russians are targeting sub-sea cables, FBI says don't let AI distract from the security basics, and more.
~ ~

Berlin in crisis response after massive data breach hits before elections
Reuters ($): Berlin is assessing the damage following a data breach involving reams of information stolen from the German city's data banks that are now on the dark web. The August cyberattack saw more than five terabytes of data exfiltrated from its systems, including citizen data and a ton of internal public records that you'd expect from a government agency. The breach was traced back to a suspected ClickFix attack; these attacks aim to trick people into hacking themselves by installing malware through terminal commands. The city's elections are to be held next week; though it's unclear if the attack was targeted or purely financially motivated, given hack-and-leak operations sometimes hit around election time. Berlin said it's not paying the ransom. 
More: DW | Heise | Medium ($) | Flying Penguin | Tuta | JD Supra

IDScan confirms hack after millions of driver's licenses stolen
TechCrunch ($): Bad news if you, uh, have a driver's license in North America, I guess? After Brian Krebs' eyewateringly good scoop from last week, the company suspected of being behind the leak, the Louisiana-based IDScan, confirmed that it had been breached. The company said that hackers stole "full names and driver’s license" or other identity numbers, like passports. Per Krebs, the breach affects over 150+ million people's driver's licenses and their photos, representing a huge and likely long-lasting breach (you can't easily change your face!). IDScan said full access to the stolen data "required payment," suggesting the hackers demanded a ransom from the company to not post the full cache after apparently siphoning the data from its systems for a year. (Disclosure: I wrote this story!) Also, in doubly bad news for Floridians: The ShinyHunters' hacking crew said it's stolen a huge cache of driver's licenses from Florida's state motor agency, which later confirmed. The hackers posted Jeffrey Epstein's expired license as proof. 
More: Risky Biz | The Record | NBC News | Bleeping Computer | Biometric Update | FLHSMV | Straight Arrow News

a screenshot of Florida's DAVID web database, showing a screenshot of the dead sex offender Jeffrey Epstein's expired driver's license.

Apple to introduce always-listening software update to new Apple Watches
Los Angeles Times ($): Apple announced during its live event on Wednesday that it will roll out always-listening features to newer Apple Watches. The features let the Watch owner recap summarized conversations from the day and rewind 15-seconds of recent audio to transcribe what was just said. Apple says the features are privacy minded and data is end-to-end encrypted, but as noted by myself and others, Apple's decision to roll out this always-recording tech normalizes the privacy invasions, effectively encouraging other tech companies to follow suit (and do a far, far worse job at storing people's data). The news sparked immediate concerns, including to note how many states and countries require consent of everyone involved before a recording can begin. I also have some words on my blog, too. 
More: Bloomberg ($) | TechCrunch ($) | CNET | Wired ($) | TechRadar | ~this week in security~ | @wendynather | @da_667 

Reporters expose secret Homeland Security "predictive policing" unit analyzing Americans' financial habits 
404 Media ($):
Incredibly important reporting by 404 Media on "predictive policing," a strand of law enforcement that once sounded like conspiratorial ramblings but is now very real because it seeks to find people who may have committed a crime but where no evidence currently exists. The publication exposed these so-called Predictive Intelligence Targeting Teams, which rely on using databases full of Americans' financial information to justify reasons for local police to carry out traffic stops and then charge them with unrelated or spurious allegations. This is a major, major undermining of probable cause, the standard that police use to stop, search, or arrest someone, per @jakelaperruque, who says "genuine probable cause cannot be synthetically generated." All to say, this is taxpayers' money going to absolute waste for schemes that broadly don't work.
More: New Republic | Marshall Project | @orinkerr | @attackerman | @pamspaulding | @josephcox

Spencer Ackerman post on Bluesky: "Extremely important story. Predictive policing is a euphemistic way of saying DHS is doing pre-crime, because of its improper access to your data. As  @jakelaperruque.bsky.social  says here, this takes a sledgehammer to the concept of probable cause of the commission of a crime. It can’t be reformed."

U.K. airports' data breach linked to publicly exposed API keys
Scott Helme: Manchester Airports Group, which operates several U.K. airports, left three API keys in the source code of its public website that allowed hackers to steal personal data of 8 million people. Scott Helme dives into how this hack-not-hack went down.

Dutch cops ask for help identifying Odido hacker
NL Times: Cops in the Netherlands are asking for help in identifying the voice of a hacker who breached Odido, the largest phone company in the country. The hacker stole the personal data of more than six million people. The cops released the audio in the hope that someone recognizes them.

a screenshot from the Dutch Police video, showing a still of the recorded call, which says as the closed caption — "It takes 15 seconds to fix the problems," as spoken by the hacker.

LG accused of privacy invasions after its smart TVs caught improperly collecting audio
The Register: Electronics giant LG has defended its products after a YouTube streamer and a security researcher analyzed an LG smart TV's network traffic and found it was still capturing audio after voice recognition was activated, including in standby mode. They also found plaintext transcripts generated from audio captured by the TV. LG said that the claims were "not true." More from The Verge ($) and Notebookcheck.

Documentation company details anatomy of a massive DDoS attack
Read The Docs: Documentation hosting company Read The Docs was hit by a sizable distributed denial-of-service attack at a pace of 5.5 million requests per minute (up from about its normal peak of 100,000 per minute). This is a pretty good write-up and post-mortem of the incident and how it handled the traffic flood, and what other future victims can do to mitigate a similar incident. (Also, it's a good time to read up on the risks of residential proxy networks used for this exact purpose!)

U.S. announces sanctions and dismantling of Xinbi Guarantee crime market
State Department: The U.S. Depts. of State, Treasury, and Justice took a massive swipe at Xinbi Guarantee, a $24 billion crime market hosted on Telegram that helped cyberscammers across southeast Asia to steal billions from people around the world through romance scams and crypto money laundering. The move by the U.S. follows U.K. sanctions earlier this year, which Wired ($) covered at the time. More words at Coindesk and Chainalysis.

A tweet by Andy Greenberg, which reads: "Telegram looked the other way as Xinbi, a $24 *billion* market for crypto scammers hosted on the messaging platform, grew into one of the biggest online black markets in history.  Now DOJ has finally sanctioned Xinbi and seized its Telegram channels," followed by a quote tweet of Greenberg's back in April, saying: "Almost 3 weeks since Telegram-based black market Xinbi Guarantee, which has done $21 *billion* in sales, was sanctioned by the UK gov for enabling crypto scamming and human trafficking. Yet Telegram, which could ban Xinbi at any time, is still hosting it."

Experts are stress-testing resiliency to GPS jamming attacks
BBC News: The BBC heads to a remote Norwegian island north of the Arctic Circle to cover Jammertest, an annual event where engineers attempt to tamper with and jam the normal running of GPS satellites. This story dives into their efforts, and why messing with satellite signals — and time-keeping itself — can determine if technology, from clocks to drones, can withstand their tests.

A bunch of hacking groups are exploiting Windows and Chrome zero-days
Bleeping Computer: Several cybercrime groups associated with China are relying on a new exploit dubbed "BlueMoon," which grants their hackers access to a victim's Windows computer by smashing through the protective sandbox in Chrome's browser. Volexity and Proofpoint have more on the activity.

Revolut falls for fake data demand: British fintech giant Revolut confirmed it gave over customer information in response to a fraudulent demand sent from a real government email. The data included personal info and users' identity documents. It's unclear how many were affected, but likely affected high net worth individuals. Crypto investigator @ZachXBT has more. (via TechCrunch ($))

a screenshot from Revolut's breach notice, which reads: "What happened? Revolut received a request for customer information that appeared to come from a legitimate government agency. The request came from an unauthorised email account sent directly using the official government agency's email domain. As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request."

Hackers mostly return stolen crypto: A hacker exploited a bug in Liquid Networks, a company that's used by a bunch of several cryptocurrency exchanges, to steal $320 million worth of bitcoin. The hacker said they'd give it back if the company fixed the bug. It did, and the hacker returned… most of it, shy about $47 million kept for themselves. (via SecurityWeek, Bloomberg ($), SiliconAngle)

1 breach + 1 million = Mathspace: Online math program Mathspace had a data breach affecting a million people, linked to an unpatched Metabase self-hosted instance . The company's breach notice was fairly candid and transparent, which is more than can be said about most companies these days.

Trezor reports a second breach: Crypto wallet maker Trezor warned that hackers stole its email subscriber list from newsletter sending partner, Brevo, which confirmed the breach. Trezor said over 347,000 people are affected and warned them to be on the lookout for an active phishing campaign. (CoinTracking and BitBox also had their email lists stolen in the same attack.) This comes weeks after a breach at shipping company ShipMonk exposed the names and home addresses of at least 81,000 people who were shipped hardware wallets, which now seems to be the root of targeted attacks. (via The Record, Bleeping Computer)

Another record Patch Tuesday: Microsoft rolled out fixes for close to a thousand bugs in its software this week in another record-breaking Patch Tuesday. The tech giant attributed once again to AI getting better at finding bugs, but experts are saying the deluge of fixes means humans can't keep up with testing and deploying. The bottom line is that security defenders desperately need more budget and resources to work with. (via Krebs on Security, Ask Woody, CSO Online

Don't let AI distract from the basics: The FBI did the media rounds this week touting its new cyber strategy, which among other things seeks more operations targeting hackers, as the feds expect AI to ramp up the speed and capabilities of cyberattacks. A key message is that AI "isn’t doing anything that attention to cybersecurity basics wouldn’t prevent." (via Nextgov, Cybersecurity Dive, Cyberscoop)

Sub-sea cable plot: NATO allies caught pesky Russian spies using an unspecified underwater "weapon" in an attempt to disable sub-sea fiber cables that carry a good chunk of the world's satellite and internet data. The cables weren't damaged, but it's suspected that the Kremlin is preparing to attempt to disrupt the internet in the event of a conflict with NATO, which, by all accounts, isn't that far off. (via Reuters ($), Euronews)

Spyware attacks target Turkish minister: At least three Turkish ministers were targeted by government spyware, citing Apple threat notifications sent to their phones. Turkish officials have been targeted with Pegasus before. Ankara said the attacks weren't successful, nor named the ministers who were targeted. (via Middle East Eye)

Good morning, good afternoon, and good evening to you wherever you are in the world! This is the happy corner, where time briefly stands still so you can catch a breather. 

Hey kids, you wanna go work at the world's largest fountain of knowledge as a new product security lead? Now's your chance to join Wikipedia. (via the very excellent @konklone)

I saw this little Bluesky bumblebee do a loop-de-loop, and I've been wanting to share it with you all week.

a screenshot showing mudscamp's post on Bluesky: "i'm bored. someone do a trick," followed by a post by Meegan, showing an emoji bee saying "ehh eh" with a bunch of emoji stars behind it as if it flew a loop.

@ernie.tedium's delightful takedown of whatever this automated hot mess is was a great read.

And, lastly, meet the dogcow Easter egg hidden in your iPhone. 

That was this week's happy corner, and now it's time to unplug

an animated GIF of a small blue desktop robot arm moving its arm towards the power cable that it's plugged into, and then pulling it out, immediately cutting the robot's power supply, freezing it on the table.

Have good news to share? Get in touch! this@weekinsecurity.com.

This week's cyber cat pupper is Bailey, who can be seen here reacting with horror after learning of someone's terrible cybersecurity posture. Fetch me a fainting couch and a password manager subscription, stat! Thanks so much to Yael G. for sending in!

Bailey is an extremely cut dog who can be seen on her hind legs with her paws out, as if to look aghast (but also incredibly adorable)

That's it for this week's edition. Thank you for reading, it means so much to me. As always, please do get in touch if you have anything for next week or an upcoming edition. And if you liked this newsletter, please share it on your ~socials~!

Have a peaceful rest of your week,
@zackwhittaker