Data Breach Roundup (Oct 3 - 8, 2026)
Frontline Education breach exposes school district employee data
Frontline Education is an edtech company that provides administration and workforce management software and services used by school districts. The company blamed the breach on a third-party software product they use, but did not offer further details. Frontline has not replied to BleepingComputer's request for comment, but sources have told the outlet that multiple districts were impacted (all employees, in some cases), exposing Social Security numbers, email addresses, and physical addresses.

Danish university DTU breach exposes data of up to 200,000 people
DTU is the Technical University of Denmark. Potentially exposed information for current users includes Danish civil registration numbers (CPR), full names, home addresses, and profile pictures, as well as work email addresses, job titles, office locations, and other employment-related details. The dataset also contained the names, relationships, and telephone numbers of users’ next of kin, when provided by active users. DTU notes that in the case of former users, details about home addresses, profile pictures, and information about next of kin are automatically deleted after six months.

CPR data breach exposes personal details of 8.8 million people in Denmark
CPR is the Danish Central Person Register. The exposed information includes names, addresses, CPR numbers and other data held in the system, according to the Ministry of Research, Education and Digitalisation. The register can contain information beyond names, addresses and CPR numbers, including marital status, birth registration details, family relationships, affiliation with the Church of Denmark and information about legal incapacitation. According to the review conducted so far, the names and addresses of people who have registered for name and address protection were not exposed.

Nikkei discloses breaches of employees’ Microsoft, Google email accounts
Nikkei is a Japanese "publishing giant." In late July, an employee's Google Workspace account was accessed, exposing the names and email addresses of 1,646 individuals (not including readers or interviewees). In September, an employee's Microsoft 365 account was also accessed and abused to send phishing emails to staff and interviewees.

ASOS confirms data breach after “HACKED” in-app notifications
ASOS is a large UK-based online fashion retailer that sells clothing, footwear, accessories, and beauty products to customers worldwide, including in the United States. ASOS has confirmed that third-party platforms used to communicate with customers were accessed without authorization and says basic personal information, including names and contact details, may have been exposed. However, the company has not confirmed the threat actor's claim that its Snowflake environment was compromised or disclosed how many customers may be affected.

Advantest confirms personal information stolen in ransomware attack
Advantest is a Japanese company that manufactures automated test equipment for the semiconductor industry. The breach happened in February 2026, and compromised contact information, dates of birth, Social Security numbers, national ID number, driver's license, passport number, medical information, financial information, and other ID numbers. It is unclear whether the compromised data belongs to customers, employees, partners, or a combination of these groups.

A Trump Mobile breach may have exposed data of more than 3,600 people
Trump Mobile - the MVNO run by the Trump family - appears to have suffered another data breach, including people who never finished signing up but still handed over email address and phone number. Impacted data includes names, home addresses, emails, phone numbers, and order information.



Community Discussion