(In)Secure Digest: a leak by official request and a $55 million bug fix

01.10.2026

We read the news, went through court cases and picked out the most interesting security incidents from September. This month’s cast includes banks that handed customer data to fraudsters themselves, developers who vibe-coded vulnerabilities into infrastructure, and cybersecurity companies without basic security rules.

Security without security rules

What happened: Attackers leaked the internal data of a cybersecurity company after compromising a former employee’s account.

How it happened: In May, hackers injected malicious code into popular TanStack npm packages. A developer at CrowdSec, a French cybersecurity company that develops open-source intrusion detection and collaborative network defence software, accidentally installed the compromised library. The employee left the company shortly afterwards as planned, but CrowdSec did not revoke access to its corporate GitHub account until several days later.

During that window, the malware managed to steal the employee’s personal OAuth token. The attackers gained access to 170 private repositories, as well as personal data belonging to more than 80 users and 50 potential CrowdSec investors.

The company discovered the breach only in September, when the data appeared on a hacker forum. CrowdSec then issued an official statement saying its infrastructure and customer databases had not been affected and that additional security measures had already been introduced.

All roads lead to Rome?

What happened: British bank Revolut voluntarily handed customers’ personal data to fraudsters.

How it happened: Hackers compromised the certified email system used by Italian authorities and spent several months sending Revolut employees official-looking requests for information. In response, bank staff provided the attackers with information on 680 major cryptocurrency holders from 33 countries.

After the breach, the attackers published documents belonging to individual customers and demanded US$3 million from the company. They said they would continue leaking information until they were paid. The investigation is ongoing.

Vibe code first, ask questions later

What happened: Hackers gained access to a company’s infrastructure and data through an application created by an employee.

How it happened: A researcher at the US organisation METR, which evaluates AI safety, vibe-coded an application and deployed it to an exposed personal EC2 instance used for testing AI agents. A bug in the code meant that anyone could gain access to the company’s AI models and an API key used with public AI services.

Attackers found the vulnerable instance and began using the API key. In total, they ran up around US$600,000 in API charges at METR’s expense without the organisation noticing. They later tried to break into internal systems and reach confidential data, but the data breach was prevented.

After the incident, METR hired a head of security, strengthened monitoring, separated the production environment for public applications from internal infrastructure, and tightened its data storage rules.

No concealing this one

What happened: A former employee tried to extort more than US$330,000 from a cosmetics manufacturer in exchange for keeping confidential information secret.

How it happened: An employee of a major Belarusian cosmetics manufacturer spent two years collecting information about the company’s financial and business activities. He then resigned, joined a competitor and began blackmailing his former employer. In exchange for keeping the information confidential, he demanded one million Belarusian rubles, or about US$330,600.

The former employee was caught red-handed during another meeting with his previous employer. He now faces up to 15 years in prison for extortion on an especially large scale.

The price of a bug

What happened: Hackers stole US$320 million from crypto company Liquid Federation.

How it happened: The attackers compromised Liquid Federation’s accounts and transferred around 96% of the company’s reserves to themselves. They then left a message for the developers: “Fix the bug first. Make sure every node is patched. Once the fix is confirmed, we’ll return the money.”

The parties discussed the vulnerability in the transaction history. The next day, the “white-hat hackers” returned US$265 million. The remaining funds appear to have been kept as a reward. The lesson is simple: write fewer bugs – at current rates, mistakes are expensive.

Fast and data-furious

What happened: Hackers posted documents belonging to 40% of US and Canadian citizens on the dark web.

How it happened: Security journalist Brian Krebs found more than 153 million scans of driving licences on the dark web, including his own licence and records linked to an FBI assistant director and the US defence secretary. He soon identified identity-verification service IDScan as the likely source of the breach.

After Krebs published his investigation and drew the FBI’s attention to the case, the company confirmed that its cloud platform had been compromised. The attackers have not yet been identified and the investigation is continuing.

Security Tip of the Month: The cosmetics-company case shows why insider risk controls matter before an employee leaves, not only after access is revoked. SearchInform Risk Monitor can record suspicious copying, transfers and other activity around confidential information, while FileAuditor helps identify sensitive files and review who has access to them. Together, these controls can help security teams spot unusual data collection before it turns into post-employment extortion.

Book a Free Trial