TL;DR for CISOs: Attackers abused a private company's lawful access to Denmark's national population register and pulled records on about 8.8 million people. Separately, South Korean banks are investigating breaches with suspected AI-assisted tooling, and attackers are exploiting a critical Rejetto HFS flaw that has had a patch since July.
- Authorized access is an attack surface. In Denmark the attackers did not defeat the register, they borrowed a partner's right to query it. Review what each third party can look up, and how fast you would notice a bulk pull.
- Volume is a signal. The Danish data protection authority described very large numbers of automated lookups. Rate and pattern monitoring on partner queries catches this class of abuse when signature-based tools do not.
- Patched is not the same as deployed. The Rejetto fix shipped in July and exploitation began in October, after proof-of-concept code appeared. Track exposure time from patch release, not from the day an exploit appears.
Lead story: Attackers abuse a private company's access to Denmark's national population register
CRITICAL · CONFIRMED BREACHAffected system: Denmark's Central Person Register (CPR), the national registry of civil registration numbers
Scale: About 8.8 million people, per BleepingComputer, The Hacker News and Cybersecurity News. TechCrunch rounds this to 8 million. The register holds roughly 11 million records, including deceased people and people who have left the country
Data involved: Names, addresses and CPR numbers; BleepingComputer also lists dates of birth and marital status. Danish authorities said the data stayed within what private companies with register access can normally receive (as reported by The Hacker News)
Method: Abuse of a private Danish company's lawful search access to the register. The Hacker News quotes the Danish data protection authority describing a very large number of automated lookups used to identify valid ID numbers
Timeline: Activity detected October 2; scope confirmed and announced by October 5. The Hacker News reports the access took place over about ten days in September; this detail comes from a single source
Response: Access for the company was blocked, police and the data protection authority are involved, and a public hotline and credit-warning option were announced (as reported by The Hacker News)
Attribution: Not disclosed. Authorities have not named the attackers or said how the company's access was obtained
What happened
Danish authorities disclosed that unauthorized parties had pulled personal data from the CPR by using a private company's approved access. Companies with a legal basis can query the register for defined purposes, such as identity verification. In this case the access was used at a scale that the register's normal usage did not expect.
Reporting differs on mechanics. BleepingComputer describes enumeration of valid CPR numbers followed by extraction of the linked records. The Hacker News attributes to the data protection authority a description of automated lookups to identify valid numbers. It is not yet public whether the partner company's credentials were stolen, its systems were compromised, or its access was misused by someone inside. Treat those as open questions.
The minister responsible called the incident very serious and, according to The Hacker News, acknowledged that safeguards around this type of access were not solid enough. Authorities warned citizens to expect phishing and social engineering that uses the exposed details.
Evidence
Verified against independently fetched sources:
1. BleepingComputer, Denmark population registry data breach affects 8.8 million people
2. The Hacker News, Denmark says attackers accessed CPR data for 8.8 million people via company account
3. Cybersecurity News, Denmark data breach exposes personal records of 8.8 million people
4. TechCrunch, Hackers steal 8 million citizens' records from Danish government database
What this means for your team
Most third-party risk programs ask whether a partner is secure. This case asks a different question: what can the partner do with the access you gave it, and who would notice if that access was used at ten thousand times the expected rate? Legitimate credentials, used through a legitimate interface, produce logs that look normal one request at a time.
The exposed fields also matter beyond Denmark. A national ID number combined with a name and address is the raw material for identity verification fraud and convincing impersonation. If your organization onboards customers or staff in affected populations, expect more attempts that arrive with correct-looking personal details.
For regulated sectors, the lesson is about governance. Access that was approved for a purpose years ago often has no usage ceiling, no expiry and no named internal owner.
- List every external party with query, API or bulk-export access to systems holding national IDs, customer identifiers or health data, and name an internal owner for each.
- Set per-partner rate limits and alert thresholds on lookups, and test whether an unusual burst would reach a person within hours.
- Require partners to report credential compromise and to rotate keys on a schedule, and write the right to suspend access immediately into the contract.
- Tighten identity verification for customers and staff in affected countries, since correct ID numbers are no longer proof of identity.
South Korean banks investigate breaches amid suspected AI-assisted attack tooling
HIGH · FINANCIAL SECTORInstitutions: Shinhan Bank, KB Kookmin Bank and Hana Bank, per BleepingComputer and The Korea Times
Reported scale: Figures differ by outlet and date. BleepingComputer reports at least 144,000 customers affected across the banks. The Korea Times reports about 25,000 at Shinhan, 119 at KB Kookmin and 89 at Hana. Confirm current numbers with the regulators before citing them
Data involved: The Korea Times lists names, phone numbers, addresses and resident registration numbers, and says transaction data was not reported as compromised
Unconfirmed claim: Some analysts suspect an open-source AI penetration-testing tool, named as ARTEX AI in the reporting, was used. This is analyst suspicion and has not been confirmed by the banks or regulators
Regulatory response: South Korea's Financial Services Commission held an emergency meeting and ordered financial institutions to inspect externally accessible systems (per BleepingComputer)
What happened
Several Korean financial institutions disclosed unauthorized access in recent days. The Korea Times reports that the affected systems were internal employee and sales-support platforms rather than customer-facing channels, and that police opened preliminary inquiries covering four institutions. Regulators ordered inspections and told firms to reduce externally exposed information and verify authentication controls.
The AI angle is attribution by analysts, not a finding. What is established is the access to internal systems and the regulatory reaction.
Evidence
Verified against independently fetched sources:
1. BleepingComputer, South Korea probes bank breaches amid suspected AI-powered attacks
2. The Korea Times, Shinhan, Kookmin, Hana data breaches fuel concerns over AI-powered cyberattacks in financial sector
What this means for your team
The reported entry point is worth your attention: employee and sales-support systems, often run by or shared with outsourced partners, tend to sit outside the controls applied to customer channels. Whether or not automated tooling was involved, faster reconnaissance shortens the time between an exposed login page and a breach.
Inconsistent public numbers are also a useful reminder. Prepare your incident communications to give a range with a stated confidence level, then update it, rather than waiting for a final count.
- Inventory internet-facing login pages for internal, partner and sales-support applications, and confirm each one enforces multi-factor authentication.
- Check password reuse and exposure for employees and outsourced staff against breached-credential data, and force resets where it matches.
- Add alerting for high-volume or machine-paced login attempts against workforce applications.
- Agree how your team will report an early, incomplete breach count to regulators and the board, and who approves revisions.
Attackers target Rejetto HFS flaw that lets them forge admin sessions
HIGH · ACTIVELY EXPLOITEDVulnerability: CVE-2026-61500 in Rejetto HTTP File Server, CVSS 9.3 per both sources
Mechanism: Session-cookie values are generated with a non-cryptographic random function, so an attacker who sees login responses can reconstruct the signing key, forge an administrator session and reach remote code execution through the server's scripting feature
Affected versions: Versions before 3.2.1; The Hacker News gives the range as 3.0.0 through 3.2.0
Fix: Version 3.2.1, available since July 2026
Exploitation: The Hacker News attributes first observed attempts to VulnCheck on October 1; SecurityWeek reports scanning as of October 2, with reconnaissance traced to China Telecom address space. Public proof-of-concept code appeared in late September
Discovery: Reporting says Horizon3.ai researcher Zach Hanley credited Anthropic's Mythos model with helping identify the flaw. Treat the extent of AI involvement as reported, not independently verified
What happened
Rejetto HFS is a lightweight file-sharing server that often runs outside central IT inventories. After a proof-of-concept became public, scanning and exploitation attempts followed within days. The patch had been out for about two and a half months.
Evidence
Verified against independently fetched sources:
1. SecurityWeek, Exploitation hits Rejetto HFS vulnerability discovered by AI
2. The Hacker News, Attackers target Rejetto HFS flaw that enables admin session forgery and RCE
What this means for your team
The gap between patch and exploit is where most organizations lose. Here it was months, and still the exposed population is enough for attackers to bother. The harder problem is shadow software: small file servers that a team stood up for convenience and nobody owns.
The reported use of an AI model in finding the flaw also signals what to plan for. If defenders and attackers both gain faster bug discovery, the time between disclosure and exploitation will keep shrinking, which makes asset visibility the control that matters most.
- Search your network and external attack surface for Rejetto HFS instances, including ones on developer machines and test servers.
- Upgrade to 3.2.1 or later, or take the service offline if no one can name a business owner.
- Review access logs since late September for unusual admin sessions or use of the server's scripting feature.
- Add a rule that any internet-reachable file server without a named owner is removed after a set review period.
Also notable
- Dell System Update: CVE-2026-86360 allows unauthenticated code execution with root privileges on systems running the tool; fixed in version 2.3.0.0. BleepingComputer notes no exploitation in the wild yet. Single source: BleepingComputer.
- Healthcare breaches: SecurityWeek reports incidents at Clover Health (138,677 people, social engineering of employee accounts) and AngMar Management Services (126,196 people, with the Interlock group claiming the theft). The ransomware group's claim is not independently confirmed. Single source: SecurityWeek.
- Citrix NetScaler follow-up: SecurityWeek reports exploitation of CVE-2026-88779 against appliances patched days earlier, with CISA's remediation date set for October 7. Covered in yesterday's edition: SecurityWeek.
- Atlassian Data Center (published October 6): CVE-2026-21589, CVSS 9.3, lets unauthenticated attackers read files across eight products; cloud services are already patched. Single source: The Hacker News.
Frequently asked questions
What data was exposed in the Danish CPR breach?
Names, addresses and civil registration (CPR) numbers for about 8.8 million people, according to BleepingComputer, The Hacker News and Cybersecurity News. BleepingComputer also lists dates of birth and marital status.
How did the attackers get in?
Danish authorities say attackers abused a private company's lawful access to search the register. How that access was obtained has not been disclosed.
Has anyone been blamed for the Denmark breach?
No. Authorities have not named the attackers and the police investigation is at an early stage.
Were the South Korean bank breaches caused by AI?
That is a suspicion voiced by some analysts and has not been confirmed by the banks or regulators. Reported customer counts also vary between outlets.
Which Rejetto HFS versions are fixed?
Version 3.2.1 and later. The flaw is tracked as CVE-2026-61500 and is reported as actively exploited.
What should a CISO do first this week?
Review third-party query and bulk-access rights on sensitive systems, find any Rejetto HFS instances, and confirm multi-factor authentication on workforce and partner logins.
Curated by Pritha Aash, Community Head, CISO Platform
Subscribe to the weekly newsletter
More from the Breach Intelligence hub, third-party risk and vulnerability management coverage on CISO Platform.
Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Comments