Six separate cyber stories landed in public view around the first week of October 2026. They are not one campaign. They do share a useful pattern: how attackers get in, how organisations talk about what was taken, and how long disclosure takes. The honest answer up front is that confirmed facts differ sharply from alleged claims in almost every case.
This combined TSN breakdown covers FortiBleed credential harvesting against Fortinet FortiGate gear [1][2]; ASOS’s unauthorised customer notifications and possible access to names and contact details [3][4]; ransomware at the University of Illinois Chicago College of Medicine [5][6]; actively exploited Citrix NetScaler vulnerabilities on CISA’s Known Exploited Vulnerabilities (KEV) catalog [7][8]; Southern Company’s notice that roughly 400,000 utility portal accounts had limited data accessed [9]; and Advantest’s October confirmation that personally identifiable information (PII) was stolen in a February ransomware incident [10].
No investment advice follows. No exploit steps, payloads or reproduction procedures appear below—only high-level public facts about impact, attribution labels and disclosure timing.
The week at a glance
| Incident | Sector / surface | Confirmed (primary) | Still alleged / open |
|---|---|---|---|
| FortiBleed | Edge firewalls / SSL VPN | FBI–USSS: ongoing credential-compromise campaign; lockouts; IAB link to named ransomware affiliates [1] | Exact global device count is SOCRadar-cited in the advisory, not re-counted by TSN [1][2] |
| ASOS | Retail customer communications | Unauthorised notification; possible names/contact access; cards/passwords not believed impacted [3][4] | Broader platform-compromise claims by threat actors (not confirmed by ASOS) [3] |
| UIC College of Medicine | Higher education / medical school IT | Ransomware; some server data obtained; main UIC network and UI Health care unaffected [5] | Booba attribution and 344 GB volume (group / press claim; not confirmed by UIC) [6] |
| Citrix NetScaler | Critical-infra edge ADC/Gateway | CISA: active exploitation; KEV entries including federal due date 7 Oct for CVE-2026-88779 [7][8] | Per-organisation compromise counts not published in the alerts cited |
| Southern Company | Utility customer portal | ~400k accounts; limited fields; no bank/card/DL numbers per company [9] | Intrusion date and access method not disclosed [9] |
| Advantest | Semiconductor test / corporate | Feb 2026 incident extracted PII; Oct notices list data types [10] | Headcount, exact cohort mix, and public leak-site appearance not published [10] |
1. FortiBleed — credential reuse at the network edge (confirmed campaign)
Confirmed. On 6 October 2026 the FBI and U.S. Secret Service published joint advisory JCSA-20261006-01 on FortiBleed: an active, global credential-compromise campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways [1].
What the agencies say, at a high level only: operators reuse previously leaked or stolen credentials against exposed FortiGate surfaces; legacy SHA-256 password storage is part of the harvesting story the advisory describes; cracked credentials are then used to create new administrative accounts; and some victims report being locked out when original account passwords are changed or accounts are removed [1]. The advisory also states that the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates, with initial access brokers (IABs) linked to INC/Lynx and Payload ransomware [1]. Cybersecurity Dive’s same-week coverage summarises the same agency warning and the SOCRadar device-scale figures the advisory cites [2].
Cited research figure (not independently re-counted here): the advisory references SOCRadar verification of more than 86,644 compromised devices across 194 countries [1][2]. Treat that as the figure agencies chose to cite, not as a TSN census.
What this does not include: TSN is not publishing indicators of compromise lists, tooling names for reproduction, or how-to guidance. Defenders should use the full FBI–USSS advisory and Fortinet’s own guidance [1].
Label summary: campaign existence, lockout behaviour and ransomware-affiliate linkage — confirmed in the joint advisory. Device totals — cited research, not a TSN count.
2. ASOS — retail customer-comms compromise (confirmed incident; alleged wider claims)
Confirmed (company and NCSC). On 6 October 2026 ASOS Plc said via Regulatory News Service that an unauthorised customer notification went out around 10am, and that it is investigating unauthorised activity involving third-party platforms used to communicate with customers [3]. Basic personal information including name and contact details may have been accessed. ASOS does not believe payment-card information or account passwords were impacted. The website and app were operating as normal; trading impact was too early to quantify; cyber insurance was noted [3].
The UK National Cyber Security Centre (NCSC) published a consumer alert the same day: customers should assume they may be affected even if they did not receive the rogue notification, watch for scams, and follow breach hygiene guidance [4]. NCSC repeats ASOS’s statement that payment cards and passwords are not believed affected [4].
Alleged / not confirmed by ASOS. Public discussion after the push notification included threat-actor framing around a broader platform compromise. ASOS’s RNS does not confirm a full core-platform breach; it frames the investigation around third-party customer-communication platforms [3]. Treat actor marketing language as alleged until the company or a regulator says otherwise.
Label summary: unauthorised notification + possible names/contacts + cards/passwords not believed hit — confirmed by ASOS/NCSC. Sweeping “everything stolen” narratives — alleged.
3. UIC College of Medicine — education ransomware (confirmed ransomware and data access; alleged volume/group)
Confirmed (university). UIC’s official notice (dated 2 October 2026 on UIC Today) states that unauthorised activity was identified on portions of the College of Medicine network, that the event was a ransomware attack, that some College of Medicine systems were temporarily unavailable and have been restored, that the main UIC network was not affected, and that there was no impact on patient care delivery at UI Health [5]. Unauthorised actors obtained some data from College of Medicine servers. Forensic review continues to determine whether personal, research or academic information was compromised; UIC says it will notify impacted individuals when that work finishes. The incident was reported to law enforcement [5].
Alleged (threat actor / secondary press). The Record reported that the Booba ransomware group claimed the attack and claimed 344 GB stolen [6]. UIC’s official notice does not name Booba or confirm that volume [5]. Attribution and size therefore remain alleged unless UIC later confirms them.
Label summary: ransomware + some server data taken + care/main network unaffected — confirmed. Booba / 344 GB — alleged.
4. Citrix NetScaler — critical-infra edge gear on CISA KEV (confirmed exploitation)
Confirmed (CISA). This is not a single named victim disclosure. It is a federal exploitation warning about edge infrastructure many organisations still expose.
On 27 September 2026 (updated 2 October), CISA amplified Citrix’s disclosure of eight NetScaler ADC/Gateway vulnerabilities (CVE-2026-88771 through CVE-2026-88778). CISA added CVE-2026-88771 and CVE-2026-88772 to the KEV Catalog: both are critical zero-days that can independently enable remote code execution, with partner intelligence confirming active global exploitation [8]. CISA urged organisations to review Citrix advisories, check for signs of compromise before patching where possible, and preserve forensics if compromise is suspected [8].
On 4 October 2026, CISA added CVE-2026-88779 (Citrix NetScaler improper restriction of operations within the bounds of a memory buffer) to the KEV Catalog based on evidence of active exploitation [7]. CISA’s KEV feed lists that CVE’s federal due date as 7 October 2026 under Binding Operational Directive (BOD) 26-04 risk-based remediation expectations for FCEB agencies [7][11]. CISA encourages all organisations—not only federal civilian agencies—to prioritise KEV remediations [7].
Label summary: active exploitation and KEV listing — confirmed by CISA. Individual victim counts for these CVEs — not stated in the alerts cited.
5. Southern Company — utility portal access for ~400,000 accounts (confirmed limited access)
Confirmed (company statement as reported). SecurityWeek reported on 7 October 2026 that Southern Company is notifying roughly 400,000 customers that an unauthorised third party accessed limited account information through its online customer portal [9]. About 300,000 accounts were Georgia Power; about 100,000 Alabama Power; Mississippi Power was also named as affected without a published count in that report [9].
Per the company notice as quoted: fields involved include name, mailing address, phone number, email, or the last four digits of Social Security Number, plus other basic account details. The company said the attacker did not access bank account numbers, payment card numbers or driver’s licence numbers. Activity was stopped on detection; law enforcement was engaged; mail/email notice and one year of free credit monitoring were offered [9].
Open. Intrusion date and access method were not disclosed in the covered statement [9].
Label summary: ~400k portal accounts, limited fields, no bank/card/DL — confirmed via company notice as reported. How access was gained — undisclosed.
6. Advantest — delayed PII disclosure after February ransomware (confirmed theft; open headcount)
Confirmed (company notices via secondary reporting of the notices). BleepingComputer reported on 7 October 2026 that Advantest Corporation’s breach notifications dated 6 October 2026 confirm that personally identifiable information was extracted during a cybersecurity incident discovered in February 2026, when an unauthorised party accessed systems and ransomware was part of the earlier public picture [10].
Data types listed in the notices include contact information, date of birth, Social Security Number, national ID number, driver’s licence, passport number, medical information, financial information and other ID numbers [10]. The company stated it had no information that the compromised data had been leaked or misused, and offered free 18-month Kroll identity/credit/web monitoring with enrolment through 4 January 2027 [10].
Open. BleepingComputer could not obtain a published headcount at the time of writing; whether affected people are customers, employees, partners or mixed was unclear; no public ransomware-group claim was found by that outlet at publication [10].
Label summary: PII extracted in the February incident — confirmed in October notices. Who and how many — not published in the coverage cited. Multi-month gap between incident discovery and individual PII notices — confirmed timeline.
Patterns across the week
Initial access → brokers / ransomware
FortiBleed is the clearest public illustration this week of a pipeline: credential harvesting and validation at the edge, packaging of access, and hand-off toward ransomware affiliates named by agencies (INC/Lynx and Payload) [1][2]. UIC sits further down a familiar arc—ransomware plus confirmed data obtained—while attribution of the group remains alleged [5][6]. Advantest is the lagged disclosure end of a ransomware-plus-exfiltration event: the theft is now confirmed even if the operator is unnamed in the coverage cited [10].
Citrix NetScaler KEV entries sit on a related but different path: vulnerability-driven edge access rather than credential reuse. CISA’s point is that unpatched ADC/Gateway surfaces are already being exploited globally [7][8]. Southern Company’s portal incident and ASOS’s third-party communications platforms show that “customer-facing systems” remain a high-value surface even when core payment databases are (claimed) untouched [3][9].
Disclosure timing
| Case | Rough public timeline | Disclosure character |
|---|---|---|
| FortiBleed | Ongoing campaign; FBI–USSS advisory 6 Oct 2026 [1] | Law-enforcement warning to defenders |
| ASOS | Same-day RNS + NCSC alert 6 Oct [3][4] | Rapid consumer/investor notice |
| UIC | Notice 2 Oct; secondary claim coverage 5 Oct [5][6] | Institutional notice; forensics still open |
| Citrix KEV | Zero-day alert late Sep; CVE-2026-88779 KEV 4 Oct, due 7 Oct [7][8][11] | Regulator-driven remediation clock |
| Southern Company | Reporting 7 Oct; intrusion date undisclosed [9] | Customer notice after investigation “to date” |
| Advantest | Incident Feb 2026; individual PII notices 6 Oct 2026 [10] | Classic delayed individual notification |
The Advantest gap is the starkest timing lesson: organisations can know they had a ransomware event months before they finish telling individuals that their PII was in the extracted set [10]. ASOS shows the opposite tempo—same-day acknowledgement when customers can see a bad notification in the wild [3][4].
What was taken vs what was not
- FortiBleed: access and credentials on edge devices; downstream ransomware risk emphasised by agencies—not a single published PII dump in the advisory itself [1].
- ASOS: possible names and contact details; payment cards and passwords not believed impacted [3][4].
- UIC: some College of Medicine server data obtained; personal/research/academic impact still under review; patient care delivery unaffected [5].
- Citrix: exploitation of edge vulnerabilities; not a named data-type disclosure in the CISA alerts [7][8].
- Southern Company: limited portal fields including name/address/phone/email or last-four SSN; bank, card and driver’s licence numbers not accessed per company [9].
- Advantest: broad PII categories including government IDs and medical/financial information listed; leak/misuse not evidenced to the company as of the notice language reported [10].
The recurring communications pattern is deliberate: organisations often stress what was not taken (cards, passwords, clinical care systems) while investigations continue on what was.
What this does not prove
- That these six events are one coordinated campaign. They share themes, not proven shared operators.
- That every FortiBleed-compromised device becomes a ransomware victim. Agencies describe a pathway used by IABs and named affiliates; they do not publish a one-to-one conversion rate [1].
- That ASOS payment systems were breached. The company and NCSC say cards and passwords are not believed impacted [3][4].
- That Booba stole 344 GB from UIC. That figure and attribution are group/press claims, not UIC’s confirmed notice [5][6].
- That Citrix KEV listings equal a known count of breached UK or US firms this week. CISA confirms exploitation evidence and remediation expectations, not a victim roster [7][8].
- Southern Company’s access method or exact intrusion date. Undisclosed in the report cited [9].
- Advantest’s affected headcount or that data is already circulating on leak sites. Not published in the coverage cited; company said it had no information of leak/misuse at notice time [10].
- Any investment thesis. Trading impact for ASOS was explicitly “too early to quantify” [3]. TSN is not offering investment advice.
The Bottom Line
This week’s cyber news is a map of surfaces, not a single outbreak. Credential reuse against internet-facing firewalls (FortiBleed) still feeds access-broker and ransomware pipelines [1][2]. Retail and utility customer channels can be hit without—according to the organisations—touching payment databases [3][4][9]. Education and corporate ransomware continue to pair encryption or disruption with data theft, sometimes with delayed individual PII notices [5][6][10]. And critical-infrastructure edge appliances remain on an active CISA KEV clock [7][8][11].
Read every headline twice: once for what the organisation or agency confirmed, and once for what threat actors or secondary reports only allege. That gap is the story as much as any single breach.
Sources
- FBI and U.S. Secret Service, Joint Cybersecurity Advisory JCSA-20261006-01, “FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts,” 6 October 2026 (PDF). https://www.ic3.gov/CSA/2026/261006.pdf
- David Jones, “FBI warns that FortiBleed credential-harvesting attacks are locking out firewall users,” Cybersecurity Dive, 7 October 2026. https://www.cybersecuritydive.com/news/fbi-fortibleed-credential-harvesting-attacks/832366/
- ASOS Plc, “Update regarding cyber incident,” Regulatory News Service via Investegate, 6 October 2026. https://www.investegate.co.uk/announcement/rns/asos–asc/update-regarding-cyber-incident-/9809595
- National Cyber Security Centre (UK), “Incident affecting ASOS customers,” 6 October 2026. https://www.ncsc.gov.uk/news/incident-affecting-asos-customers
- University of Illinois Chicago, “College of Medicine systems compromised,” UIC Today, 2 October 2026. https://today.uic.edu/college-of-medicine-systems-compromised/
- Jonathan Greig, “University of Illinois Chicago affected by ransomware attack on medical school,” The Record (Recorded Future News), 5 October 2026. https://therecord.media/ransomware-university-illinois-chicago
- CISA, “CISA Adds One Known Exploited Vulnerability to Catalog” (CVE-2026-88779), 4 October 2026. https://www.cisa.gov/news-events/alerts/2026/10/04/cisa-adds-one-known-exploited-vulnerability-catalog
- CISA, “Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway” (CVE-2026-88771 / CVE-2026-88772 and related), 27 September 2026, updated 2 October 2026. https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
- Eduard Kovacs, “Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts,” SecurityWeek, 7 October 2026. https://www.securityweek.com/georgia-power-alabama-power-data-breach-hits-400000-accounts/
- Bill Toulas, “Advantest confirms personal information stolen in ransomware attack,” BleepingComputer, 7 October 2026. https://www.bleepingcomputer.com/news/security/advantest-confirms-personal-information-stolen-in-ransomware-attack/
- CISA Known Exploited Vulnerabilities Catalog feed (due dates for CVE-2026-88771, CVE-2026-88772, CVE-2026-88779 verified from catalog JSON), accessed 7 October 2026. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
