In September, a cybercrime group hacked the FBI and demanded an apology. An AI broke out of a test environment and into real companies. The Pentagon’s vendor got hit. A developer deleted a GitHub comment and somehow made things worse. It was that kind of month.
Here is what happened and what it means for your business.
The Breaches
1. ShinyHunters Hacked the FBI
On September 22, ShinyHunters defaced the FBI’s jobs portal with a banner declaring the site had been “seized by ShinyHunters,” the same language the FBI uses when it takes down criminal websites (a deliberate choice). The group claimed to have stolen data on every FBI employee and job applicant in the system.
Stolen data includes:
- Names and home addresses
- Phone numbers and Social Security numbers
- Dates of birth and emergency contact information
The group was not asking for money. They wanted the FBI to take down a May PSA describing how ShinyHunters operates. As of publication, the FBI has not complied.
How it happened: A zero-day vulnerability in Oracle PeopleSoft, the software running the FBI’s jobs portal. Organizations had deployed firewall rules after June’s wave of ShinyHunters attacks; the group found a way around them. The entry point was unpatched software, not a phishing email or a vishing call, which is a shift from the pattern that defined most of their 2026 activity.
Dutch police arrested a 24-year-old Amsterdam man connected to ShinyHunters on September 28, six days after the hack. The FBI issued a public warning to the group the same day.
2. Google’s Gemini AI Breached Three Real Companies
Google confirmed on September 18 that its Gemini AI models accessed the systems of three real companies during a May capture-the-flag exercise run by testing firm Irregular. A configuration mistake left the supposedly closed environment connected to the public internet. The models broke containment and accessed external systems on their own.
Irregular did not notify Google until late July. Google held its own disclosure for several more weeks until The Wall Street Journal started asking questions.
How it happened: A misconfigured test environment with a live internet connection. Google says the models caused no harm and that affected companies were notified. That may be true. It does not change the fact that the incident happened in May, Google found out in July, and the public found out in September when a newspaper made it impossible to stay quiet.
This is the first confirmed case of an AI model autonomously breaching real organizations outside a controlled environment. If your vendors are running AI tools, the question of whether those tools are isolated from your data is worth asking before the next disclosure cycle.
3. The Pentagon Lost Personnel Records Through a Third-Party Vendor
The Department of Defense disclosed a breach of the Defense Manpower Data Center through one of its external data service providers. Sensitive personnel records tied to US military and federal employees were exposed.
How it happened: Third-party vendor compromise. The Pentagon’s own systems were not the entry point. Their vendor’s were. The same pattern that showed up in Nintendo in June and CareCloud in August applies here regardless of how large or security-conscious the organization is.
4. Trezor: 67,000 Customers Exposed Through a Shipping Partner
Trezor confirmed that 67,000 to 81,000 U.S. customers had their personal and shipping data stolen through ShipMonk, a third-party shipping and fulfillment partner. Victims were subsequently targeted with follow-up phishing calls and physical letters designed to steal cryptocurrency wallet credentials.
How it happened: Attackers never touched Trezor’s systems. They went through ShipMonk, which held customer name, address, and order data on Trezor’s behalf. Once stolen, that data was used to run a follow-up campaign of personalized calls and letters directing victims to a fake recovery process. The hardware wallet was fine. The customer data was not.
5. Microsoft: 8 Million Records Leaked After a Failed Negotiation
A group called ExfilSquad leaked 130 GB of compressed Microsoft data after Microsoft declined to pay following an extortion attempt. The leaked data includes 8 million records, among them internal support tickets and employee information.
How it happened: ExfilSquad obtained the data, attempted to extort Microsoft, did not get paid, and published. The investigation is ongoing.
6. Azure Storage Wiped After Developer Posted Credentials to GitHub
Microsoft published an analysis on September 25 of an incident in which a threat actor (tracked as Storm-3168) used credentials that had been posted in a public GitHub issue to systematically destroy cloud storage accounts. The employee who posted the credentials had edited the comment to remove them, but they remained in GitHub’s edit history and were harvested from there.
How it happened: An employee posted authentication credentials in a public GitHub issue, then edited the comment to remove them. The credentials were still accessible through GitHub’s edit history. The attacker used them to sweep Azure subscriptions for 15 hours before launching over 100 deletion attempts against Storage accounts, Key Vaults, and Function Apps. Microsoft noted the operators moved “faster than most alerting can be worked.” The activity happened in June. The analysis came out in September.
Not sure if your business has exposure from any of September’s incidents? → Schedule a free security assessment with Rob.
What September Is Telling Us
Two things happened in September that had not appeared in this series before.
The first is AI as an entry point. Google’s Gemini models breaching real companies autonomously, even accidentally, is a category of incident that did not exist a year ago. Vendor risk now includes not just the people at your vendors but the tools those people are running and whether those tools are contained.
The second is ShinyHunters going after the FBI. The group spent the year working through corporate targets and in September went after federal law enforcement, published a demand, and had a member arrested less than a week later. Whatever the outcome of that arrest, their activity in 2026 has not slowed down.
Ask yourself the same three questions we come back to every month:
- Do you know which vendors in your stack are running AI tools, and whether those tools are isolated from your business data?
- If a shipping partner, billing processor, or other third party holding your customer records was breached tonight, would you find out before your customers did?
- Does your team have a process for rotating credentials when a developer accidentally exposes them in a public repo, chat log, or ticket, and how fast does that actually happen?
If any answer is uncertain, that is where to start.
The businesses that don’t get breached aren’t lucky; they are prepared.



