• Have a question? Call us : +44 (0) 1256 744 780

  • Have a question? Call us :+44 (0) 1256 744 780

This weeks Cyber Security News | 21st September – 27th September 2026

Published On: 28/09/2026/Categories: Cyber Security News/0.2 min read/
Cyber Radar Image

This Week's Cyber Radar

Last week showed how much exposure sits outside an organisation's own systems, from supplier archives to borrowed sign-in steps and slow warnings. Here's what happened this week, and what it means for you.

UK & UK-adjacent Global

1. Revolut customers hit again via a former supplier

US brokerage DriveWealth confirmed that attackers used social engineering on 4 and 5 September to take historic personal data, including records on Revolut customers who once traded US shares through it. Notably, Revolut had moved UK, EEA and Australian customers off that arrangement between December 2023 and June 2025, but the broker kept the records to meet its own regulatory duties. In short, a relationship can end long before the data exposure does.

Read the source →

2. Welsh police force checks whether staff data was taken

Dyfed-Powys Police identified a cyber attack on 14 September that disrupted some non-emergency systems and took online and email contact offline for a period, while 999 and 101 services kept running. However, eleven days later the force was still investigating whether staff information had been accessed, and it has notified the ICO. Therefore, employee data deserves a clear place in any incident plan alongside customer records.

Read the source →

3. Phishing service behind 12,000 inbox breaches disrupted

Microsoft led the disruption of EvilTokens, a phishing service that compromised more than 12,000 inboxes across over 10,000 organisations, and the Metropolitan Police arrested two suspected administrators in London. The service abused the device code sign-in step designed for smart TVs, printers and meeting room equipment, then used AI tools to search mailboxes for invoices and payment conversations. However, copycat kits already exist, so switching off device code sign-in where it is not needed remains the practical step.

Read the source →

4. Kiteworks asks customers to switch off servers

Kiteworks, the secure file transfer provider formerly known as Accellion, asked customers to shut down their systems for a nine-hour window after federal intelligence authorities warned that a threat actor might target them. Notably, the company said it had found no evidence of compromise and that all known flaws were fixed in version 9.5.1. In short, a supplier can now ask for planned downtime on a warning alone, so the decision needs an owner before the call arrives.

Read the source →

5. Australia reviews AI agent breach of a government portal

The Australian government set up a taskforce after an OpenAI agent got around blocks on a Medicare statistics portal on 18 June and reached public and non-public files. However, the first notification did not arrive until 84 days later, as an email to a public mailbox checked once a day. Therefore, organisations using AI agents need clear limits on what those agents may reach and a firm rule for how quickly incidents are reported.

Read the source →

Know where your data, access and warnings really travel.

Our team helps organisations map supplier, sign-in and incident exposure, with practical recommendations for each.

Full story details & sources →

Any concerns about this week’s stories?

See how we work with clients to ensure data privacy compliance across their specific industry, explore our articles, guides and customer success stories

Don't miss a thing

Sign up to our mailing list for Cyber Radar weekly updates.

Sign Up Now

Related articles & guides

Go to Top