HomeAICyber breaches, 8 October: court files, hijacked domains, a patched-but-probed flaw, church...

Cyber breaches, 8 October: court files, hijacked domains, a patched-but-probed flaw, church records and a $10m reward

Seven separate cyber stories surfaced on 6–7 October 2026. They are not one campaign. The pattern worth reading is how attackers got in, who confirmed what, and how much still rests on allegations.

This TSN roundup covers the Arizona court system’s confirmation that data on more than 1.3 million people was copied [1]; registry hijacks in the .gh, .sl and .as country-code domains that let attackers obtain certificates for Google and other organisations [2]; exploitation attempts against a critical Atlassian flaw within hours of a public proof of concept [3][4]; Yoido Full Gospel Church’s confirmation that 850,000 members’ data was exposed [5]; a breach at the Double Counter Discord bot [6]; fraud charges against the owner of ransomware-recovery firm MonsterCloud [7]; and a $10 million US reward for accused HAFNIUM hacker Zhang Yu [8].

No exploit steps, payloads, indicators or reproduction details appear below, and no investment advice follows.

The week at a glance

IncidentSector / surfaceConfirmed (primary or on-record)Still alleged / open
Arizona courtsState judiciaryBackup files copied; 1.3m people in fines/fees data; foster-care reports accessed; phishing start [1]No group has claimed; court says file format may limit readability [1]
.gh/.sl/.as hijacksDNS / web certificatesRegistries compromised; unauthorised certificates for Google and other domains; Chrome blocked them [2]Full list of affected domains; Google says it cannot guarantee it found all [2]
Atlassian CVE-2026-21589Self-hosted Data Center softwareCritical flaw; fixes issued 5 Oct [3]Exploitation attempts reported by one firm’s honeypots; not on CISA KEV as of TSN’s check [3][4]
Yoido Full Gospel ChurchReligious organisation, South Korea850,000 members’ names and birth dates in one exposed data set [5]Admin-level server access and wider data volumes alleged by a threat-intel firm [5]
Double CounterDiscord bot~12 GB copied; bot token hijacked; links posted in ~50 servers [6]Number of affected users not stated in coverage [6]
MonsterCloudRansomware recovery servicesIndictment and not-guilty plea [7]All fraud claims are allegations [7]
Zhang Yu / HAFNIUMState-linked espionage$10m State Department reward [8]Charges are accusations; Zhang remains at large [8]

1. Arizona courts: 1.3 million people’s data copied after a phishing click (confirmed)

Confirmed (court FAQ, as reported). Arizona court officials said in an updated FAQ this week that federal and state investigators confirmed criminal hackers “accessed and copied backup court files,” The Record reported on 7 October [1].

What was hit, per the court’s statements as reported [1]:

  • Fines/Fees and Restitution Enforcement (FARE) Program: names, Social Security numbers and case numbers of 1.3 million people, with records going back 30 years. Victims will be notified by text and are urged to place holds on their credit.
  • Foster Care Review Board reports: more than 150,000 reports on current and past cases dating back to 2010, including 8,000 children currently in foster care. The reports include information on children, family statements, investigative findings and administrative notes.
  • Protective orders: records on active and inactive protective orders, including some sensitive information.

How it started. Investigators believe the attack began with phishing: a court employee clicked a malicious link in an email [1]. The Arizona Supreme Court announced the breach on 25 September, saying the attack began on 24 September and continued until IT staff shut the system down [1].

Open. No group has claimed the attack; a court spokesperson previously said it did not involve ransomware and no ransom demand had been made [1]. The court says the format of the stolen files may make them hard to read; that is the court’s assessment, not an independent finding [1].

Label summary: copying of backup files, 1.3 million FARE records and foster-care reports — confirmed. Readability of the stolen files — court claim.

2. ccTLD registry hijacks: unauthorised certificates for Google and others (confirmed by Google)

Confirmed (Google). In a 6 October blog post, Chrome’s Secure Web and Networking team said that in the previous week attackers hijacked domains in the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) country-code top-level domains [2].

What Google says happened, at a high level [2]:

  • The attackers compromised the third-party ccTLD registries, not Google’s systems, putting any domain ending in those suffixes at risk.
  • They changed authoritative DNS records and obtained unauthorised HTTPS certificates for several Google domains and for domains of other organisations.
  • Google says it has “no reason to believe” the certificate authorities that issued the certificates did anything wrong, given the nature of the attack.

Chrome’s response. Google blocked the unauthorised certificates for Google properties in Chrome via CRLSets (Chrome’s built-in list of blocked certificates) and worked with the issuing authorities to revoke them for other browsers [2]. Certificate Transparency logs then revealed more affected organisations, including “several leading global brands and widely used online services”; Google says it blocked those certificates too and contacted organisations where possible [2]. Chrome users need take no action [2].

The caveat Google adds itself. It “cannot guarantee” its analysis found every affected domain, and Chrome’s interventions do not protect non-Chrome users [2]. Google advises domain owners to monitor Certificate Transparency logs for all their domains and to publish restrictive CAA records, which state which certificate authorities may issue for a domain [2].

Label summary: registry compromise, unauthorised certificates and Chrome blocking — confirmed by Google. Full victim list — not published.

3. Atlassian CVE-2026-21589: exploitation attempts after a public PoC (reported)

Confirmed (vendor fix, as reported). Atlassian disclosed CVE-2026-21589, a critical, unauthenticated arbitrary file-access flaw, on Monday 5 October, and urged administrators of self-hosted instances to apply security updates as soon as possible [3]. BleepingComputer lists eight affected self-hosted products: Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd Data Center, plus Crucible and Fisheye [3]. Atlassian said it cannot determine whether individual customer instances have been compromised [3].

Reported (security firm). Security company Previdian told BleepingComputer that its honeypot network began observing exploitation attempts within about two hours of a security research firm publishing a detailed technical write-up and public proof of concept on 7 October [3]. Researchers said that, in certain configurations, the flaw could be used to reach administrator-level access [3]. Previdian expects activity to increase over the coming days and weeks [3].

CISA KEV status. As of TSN’s check of CISA’s Known Exploited Vulnerabilities catalog feed on 8 October 2026 (catalog version 2026.10.04), CVE-2026-21589 was not listed [4]. Absence from KEV does not mean the flaw is safe to leave unpatched.

What TSN is not publishing. The coverage includes technical detail on how the flaw works, indicators and scanning templates. TSN is deliberately omitting all of it. Administrators should use Atlassian’s own bulletin for fixed versions and mitigations [3].

Label summary: critical flaw and fixes — confirmed by Atlassian. Exploitation attempts — reported by one firm’s honeypots. Confirmed victim compromises — none published. KEV — not listed at time of check.

4. Yoido Full Gospel Church: 850,000 members’ data exposed (confirmed exposure; alleged admin access)

Confirmed (church statement, as reported). Yoido Full Gospel Church in Seoul said on 7 October that, after analysing suspected leaked data and access logs with an outside security firm, one of seven suspected data sets, “Member Information Change History”, contained personal information: the names and dates of birth of 850,000 members, plus change records including 2,629 resident-registration-number changes, 3,964 phone-number changes and 7,202 address changes, The Asia Business Daily reported [5].

The church said the other six data sets (district transfers, church appointments, baptisms, donation records from 1993 to 2019 and salary records) contained no personally identifying information [5]. It received notice from the Korea Internet & Security Agency (KISA) at 3pm on 6 October (07:00 BST), blocked external access and changed server passwords at 1am on 7 October (17:00 BST on 6 October), and is notifying members individually [5]. Senior pastor Lee Young-hoon apologised [5].

Alleged (threat-intelligence firm). Oasis Security, which found the data on a server used by overseas attackers, claims the attacker used a web shell (a malicious server-side program) to get into the church’s enterprise resource planning (ERP) server and obtain database administrator privileges [5]. The firm also says it found about 960,000 member-related records, about 330,000 donation records and about 47.3 GB of related data, including some 68,000 electronic approval documents and 14,706 internal messenger conversations [5]. The Asia Business Daily notes that the 960,000 figure uses different counting from the church’s 850,000 [5].

The same firm says it found data on about 89,000 members and 286 employees of SaRang Church, also in Seoul; that church has reported the incident and agencies are investigating [5].

Label summary: 850,000 members’ names and birth dates exposed — confirmed by the church. Web-shell entry, admin privileges and wider data volumes — alleged by Oasis Security.

5. Double Counter: a Discord bot breached and hijacked (confirmed by the operator)

Confirmed (operator statement, as reported). Double Counter, a Discord server-privacy bot, says hackers copied about 12 GB of data, including Discord usernames and user IDs, IP addresses, location data and email addresses, The Verge reported on 7 October (13:48 BST) [6].

The attackers also took control of the bot’s Discord token, posted links “in about 50 large servers”, and “used a stolen payment key to commit financial fraud on a separate account,” according to the bot’s statement [6].

Open. The number of affected users and how the attackers got in were not stated in the coverage checked [6].

Label summary: data copied, token hijack and links posted — confirmed by the operator. User count and entry route — not disclosed.

6. MonsterCloud owner charged over secret ransom payments (allegations only)

Confirmed (court process). Zohar Pinhasi, 50, owner of Florida-based ransomware-remediation firm MonsterCloud, was indicted by a federal grand jury in the Eastern District of New York on 23 September and arraigned on 7 October in Brooklyn, BleepingComputer reported [7]. He faces one count of conspiracy to commit wire fraud and two counts of wire fraud. The US Attorney’s Office said he surrendered, pleaded not guilty, and was released on a $2 million bond [7].

Alleged (indictment). Prosecutors allege that from June 2018 to June 2023 MonsterCloud advertised proprietary decryption technology it did not have, and instead paid ransomware operators for decryption keys while billing victims far more [7]. Over the period, prosecutors say, the company facilitated more than $8 million in ransom payments while charging hundreds of US and Canadian companies more than $19 million [7]. One example cited: a ransom of about $8,200 allegedly paid while the victim was charged about $150,000 [7]. The indictment acknowledges some contracts disclosed that the company might pay criminals [7].

BleepingComputer contacted Pinhasi’s lawyers for comment [7]. A 2019 ProPublica investigation raised similar concerns, which Pinhasi disputed at the time [7].

Label summary: indictment, arraignment and not-guilty plea — confirmed. Everything about the alleged scheme — allegations that have not been proven in court.

7. $10 million reward for accused HAFNIUM hacker Zhang Yu (confirmed reward; accused)

Confirmed (State Department reward, as reported). The US State Department is offering $10 million for information on the whereabouts of Zhang Yu, a Chinese national accused of being a key figure in the HAFNIUM hacking campaign, The Record reported on 7 October [8].

Accused (US officials and indictment). US officials say Zhang, director of Shanghai Firetech Information Science and Technology, worked for the Chinese government; a nine-count indictment unveiled last year accused Zhang and Xu Zewei of intrusions between February 2020 and June 2021, including HAFNIUM, and of stealing COVID-19 research from US universities and researchers [8]. Prosecutors say the hacks were directed by China’s Ministry of State Security and the Shanghai State Security Bureau [8]. Xu was arrested in Italy in July 2025 and extradited to the US in April; Zhang remains at large [8].

Label summary: reward — confirmed. Hacking charges — accusations, not convictions.

Patterns across the week

Initial access: people, registries and unpatched servers

Three different doors: a phishing click at Arizona’s courts [1]; a compromise upstream, at the country-code registries, that let attackers redirect domains they never touched directly [2]; and an unpatched, internet-facing server at risk once technical detail went public [3]. The Yoido case, if Oasis Security’s account is right, adds a fourth: a web shell on a business-system server [5].

The patch-to-exploit window keeps shrinking

Atlassian’s fix landed on 5 October; reported exploitation attempts began within about two hours of a public write-up on 7 October [3]. For defenders, the lesson is that a vendor advisory starts the clock, and a public PoC speeds it up.

Disclosure timing

CaseRough public timelineDisclosure character
Arizona courtsAttack 24 Sep; announced 25 Sep; scope FAQ this week [1]Staged disclosure as forensics advance
ccTLD hijacksHijacks “last week”; Google post 6 Oct [2]Vendor incident report after mitigation
AtlassianAdvisory 5 Oct; PoC and attempts 7 Oct [3]Vendor-first, then researcher, then attackers
YoidoKISA notice 6 Oct; church statement 7 Oct [5]Fast acknowledgement after external tip
Double CounterStatement reported 7 Oct [6]Operator self-disclosure
MonsterCloudIndicted 23 Sep; arraigned 7 Oct [7]Court process
Zhang YuIndictment last year; reward 7 Oct [8]Law-enforcement pressure

What this does not prove

  • That these seven events are linked. They share themes, not proven operators.
  • That Arizona’s stolen files are unreadable. That is the court’s assessment [1].
  • That certificate authorities or Google’s own systems were breached. Google says neither was the case [2].
  • That any Atlassian customer has been compromised via CVE-2026-21589. Reported activity is exploitation attempts against honeypots; no victim has been published [3]. Its absence from CISA KEV at the time of TSN’s check is not evidence of safety [4].
  • That attackers had database-admin access at Yoido, or that 960,000 records or 47.3 GB were taken. Those are Oasis Security’s claims; the church confirmed 850,000 members’ names and birth dates [5].
  • How many Discord users Double Counter’s breach affects. Not stated [6].
  • That Zohar Pinhasi or Zhang Yu committed the crimes alleged. Both are accused; Pinhasi has pleaded not guilty [7][8].
  • Any investment conclusion. TSN offers no investment advice.

The Bottom Line

This week’s cyber news runs from the very human (a court employee’s phishing click [1]) to the deeply structural (country-code registries hijacked to mint certificates for big-brand domains [2]). In between: a critical Atlassian flaw probed within hours of a public write-up [3]; a church confirming 850,000 members’ records exposed while a security firm alleges far deeper access [5]; a hijacked Discord bot [6]; a recovery firm owner accused of quietly paying ransoms [7]; and a $10 million reward for an accused state hacker [8].

As last week, read every headline twice: once for what was confirmed, and once for what is only alleged.

Related on TSN: Cyber breaches this week: credential reuse, retail alerts, campus ransomware and edge-gear risk (https://tsnmedia.org/cyber-breaches-week-7-october-2026/).

Sources

  1. Jonathan Greig, “Arizona courts say hackers stole info on more than 1.3 million people,” The Record (Recorded Future News), 7 October 2026. https://therecord.media/arizona-courts-say-hackers-stole-info-on-over-1-million
  2. Chrome Secure Web and Networking Team, “Chrome’s Response to Recent ccTLD Registry Hijacks,” Google blog, 6 October 2026. https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/
  3. Bill Toulas, “Hackers exploit critical Atlassian flaw after public PoC release,” BleepingComputer, 7 October 2026. https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-atlassian-flaw-after-public-poc-release/
  4. CISA, Known Exploited Vulnerabilities Catalog (JSON feed, catalog version 2026.10.04; CVE-2026-21589 not present), accessed 8 October 2026. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  5. Kim Heeyun, “Yoido Full Gospel Church Hacked; Names, Birth Dates of 850,000 Members May Have Been Exposed,” The Asia Business Daily, 7 October 2026. https://www.asiae.co.kr/en/article/2026100715462417960
  6. Stevie Bonifield, “Discord users’ data was exposed in a breach at server bot Double Counter,” The Verge, 7 October 2026. https://www.theverge.com/tech/1006670/discord-users-data-was-exposed-in-a-breach-at-server-bot-double-counter
  7. Lawrence Abrams, “Ransomware recovery CEO charged over secret ransom payments,” BleepingComputer, 7 October 2026. https://www.bleepingcomputer.com/news/security/ransomware-recovery-ceo-charged-over-secret-ransom-payments/
  8. Jonathan Greig, “US posts $10 million reward for accused Chinese ‘Hafnium’ hacker,” The Record (Recorded Future News), 7 October 2026. https://therecord.media/accused-hafnium-hacker-zhang-yu-10million-reward

Share this story

More in this category

Latest on TSN

Free TSN tools: crypto calculator, Flux dashboard and more.