Data Breach Roundup (Oct 3 - 8, 2026)

Data Breach Roundup (Oct 3 - 8, 2026)

Frontline Education breach exposes school district employee data

Frontline Education is an edtech company that provides administration and workforce management software and services used by school districts. The company blamed the breach on a third-party software product they use, but did not offer further details. Frontline has not replied to BleepingComputer's request for comment, but sources have told the outlet that multiple districts were impacted (all employees, in some cases), exposing Social Security numbers, email addresses, and physical addresses.

Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers.

Danish university DTU breach exposes data of up to 200,000 people

DTU is the Technical University of Denmark. Potentially exposed information for current users includes Danish civil registration numbers (CPR), full names, home addresses, and profile pictures, as well as work email addresses, job titles, office locations, and other employment-related details. The dataset also contained the names, relationships, and telephone numbers of users’ next of kin, when provided by active users. DTU notes that in the case of former users, details about home addresses, profile pictures, and information about next of kin are automatically deleted after six months.

Danish university DTU breach exposes data of up to 200,000 people
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data.

CPR data breach exposes personal details of 8.8 million people in Denmark

CPR is the Danish Central Person Register. The exposed information includes names, addresses, CPR numbers and other data held in the system, according to the Ministry of Research, Education and Digitalisation. The register can contain information beyond names, addresses and CPR numbers, including marital status, birth registration details, family relationships, affiliation with the Church of Denmark and information about legal incapacitation. According to the review conducted so far, the names and addresses of people who have registered for name and address protection were not exposed.

CPR data breach exposes personal details of 8.8 million people in Denmark - The Copenhagen Post
Unauthorized parties gained access to personal information linked to around 8.8 million people in Denmark after exploiting a company’s legitimate access to the country’s Central Person Register, authorities said Monday. The exposed information includes names, addresses, CPR numbers and other data held in the system, according to the Ministry of Research, Education and Digitalisation. The […]

Nikkei discloses breaches of employees’ Microsoft, Google email accounts

Nikkei is a Japanese "publishing giant." In late July, an employee's Google Workspace account was accessed, exposing the names and email addresses of 1,646 individuals (not including readers or interviewees). In September, an employee's Microsoft 365 account was also accessed and abused to send phishing emails to staff and interviewees.

Nikkei discloses breaches of employees’ Microsoft, Google email accounts
Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails.

ASOS confirms data breach after “HACKED” in-app notifications

ASOS is a large UK-based online fashion retailer that sells clothing, footwear, accessories, and beauty products to customers worldwide, including in the United States. ASOS has confirmed that third-party platforms used to communicate with customers were accessed without authorization and says basic personal information, including names and contact details, may have been exposed. However, the company has not confirmed the threat actor's claim that its Snowflake environment was compromised or disclosed how many customers may be affected.

ASOS confirms data breach after “HACKED” in-app notifications
UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company’s Snowflake environment.

Advantest confirms personal information stolen in ransomware attack

Advantest is a Japanese company that manufactures automated test equipment for the semiconductor industry. The breach happened in February 2026, and compromised contact information, dates of birth, Social Security numbers, national ID number, driver's license, passport number, medical information, financial information, and other ID numbers. It is unclear whether the compromised data belongs to customers, employees, partners, or a combination of these groups.

Advantest confirms personal information stolen in ransomware attack
Advantest Corporation is notifying affected individuals that a ransomware attack earlier this year exposed their personally identifiable data.

A Trump Mobile breach may have exposed data of more than 3,600 people

Trump Mobile - the MVNO run by the Trump family - appears to have suffered another data breach, including people who never finished signing up but still handed over email address and phone number. Impacted data includes names, home addresses, emails, phone numbers, and order information.

A Trump Mobile breach may have exposed data of more than 3,600 people
The BYOD hacking group claims responsibility.

Community Discussion