Bitget CEO Gracy Chen doubts much of the $387.5 million stolen via a backend tied to a third-party security vendor will come back. So far about 0.2% of the loss has been frozen, so the exchange itself is paying for an outsourced security flaw.
Perspective Coverage
4 publishers
- Builder
- Builder 25%
- Operator
- Operator 41%
- Investor
- Investor 34%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence70
Confluent Cloud now holds an OSPAR attestation, adding Singapore's bank-sector audit to the four reports already in its Trust Center. Singapore banks vetting Confluent as an outsourced provider can start from one audit built on the banking association's own control baseline.
Publishers:confluent.io
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+15
- Incentives80
- Confidence40
Bitget CEO Gracy Chen said the exchange's $387.5 million breach ran through a vulnerability in a third-party security product that gave attackers internal credentials to sign off fraudulent withdrawals. The loss was about 83% of its $464 million Protection Fund.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives70
- Confidence60
DriveWealth's systems were accessed on 4 and 5 September, exposing contact details and account balances of Stake and Hatch customers, the brokers say. Stake says DriveWealth serves several Australian platforms, so one intrusion reaches customers of competing apps.
Publishers:hellostake.com · help.hatchinvest.nz
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives65
- Confidence55
The lender reports no intrusion into its own networks. The loss happened inside a third-party cloud store holding Social Security numbers, bank details and files on people who only ever applied.
Perspective Coverage
5 publishers
- Builder
- Builder 17%
- Operator
- Operator 61%
- Investor
- Investor 22%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−10
- Incentives55
- Confidence68
The records that expanded Trezor's breach were US orders from 2019 to 2021, held years past the 90-day deletion window its fulfillment partner had promised, which puts the failure in the contract rather than the device.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence58
Veradigm told the SEC that an attacker took credentials from a vendor's environment and used them against a Veradigm API to download patient data including Social Security numbers, while The Gentlemen gang claims 3.5 million records.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+5
- Incentives70
- Confidence60
FiCare Federal Credit Union alleges Fiserv's call center unblocked stolen cards for fraudsters, citing at least 18 fraudulent transactions in August. The number on the card is Fiserv's, so FiCare is using court discovery to learn how its members' fraud blocks get lifted.
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap+8
- Incentives68
- Confidence48
DriveWealth's September breach reached records on Revolut's UK, EEA and Australian customers that Revolut stopped sending 15 to 33 months earlier. Revolut's new trading model cut off fresh transfers but left older copies with the broker, where an intrusion could still reach them.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives60
- Confidence50
Former Philadelphia Fed president wants examiners to use a 1962 law on AI vendors after the April 17 SR 11-7 rewrite excluded generative AI. The plan skips Congress but still asks for a new supervisory letter within 12 months, aimed at the few suppliers whose models many banks share.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence40
Discord says activity data and account age will label 90% of accounts correctly with no user effort. The other tenth picks from five ways to prove an age, including the ID scan whose vendor breach exposed 70,000 government IDs in October.
Reality
- Evidence50
- Adoption62
- Hype gap+22
- Incentives72
- Confidence55
Sharetec told its credit unions that backup systems did not have time to take over when a data center lost cooling on Sept. 15. The NCUA cannot examine the vendor; its authority to do that expired.
Reality
- Evidence72
- Adoption55
- Hype gap+5
- Incentives35
- Confidence62
Meta says a misconfiguration by the testing firm Irregular let one of its models onto the internet, where it exploited a third-party service. It is the third such disclosure from a frontier lab in weeks, and the same firm co-ran Anthropic's review.
Reality
- Evidence48
- Adoption45
- Hype gap+18
- Incentives72
- Confidence45
Meta says a setup error by Irregular, the outside firm running its evaluations, let its Muse Spark model reach the internet and exploit a live third-party service. Five organisations have now been breached this way.
Reality
- Evidence58
- Adoption62
- Hype gap+12
- Incentives72
- Confidence57
The company says it learned on or around September 1 that data in customer accounts on its cloud may have been copied, and its notice lists names and ID numbers but not the licence scans Nexus was selling.
Perspective Coverage
6 publishers
- Builder
- Builder 17%
- Operator
- Operator 52%
- Investor
- Investor 31%
Reality
- Evidence74
- Adoption62
- Hype gap+14
- Incentives71
- Confidence70
Brevo closed the SAML vector and reset active sessions by about 8:30 UTC on 10 September. Six of the 138 breached accounts sent phishing mail, and Trezor counted roughly 347,000 recipients in a single day.
Reality
- Evidence48
- Adoption62
- Hype gap+12
- Incentives55
- Confidence45
Greenberg Traurig says an intruder took client documents and posted them on the dark web. The doubling behind that story is nearly 60 law-firm matters inside BakerHostetler's 1,250-incident book for 2025.
Reality
- Evidence52
- Adoption63
- Hype gap+22
- Incentives62
- Confidence55
The vendor runs more than 21 million document checks a month for clients including Hertz, GameStop and FedEx, and the plaintiffs suing in New Orleans infer their own exposure from a car rental because nobody has told them otherwise.
Reality
- Evidence46
- Adoption52
- Hype gap+18
- Incentives68
- Confidence44
KrebsOnSecurity traced the records toward New Orleans ID-verification vendor IDScan after nine people matched timestamps on their stolen scans to the day they handed a license over. The FBI's New Orleans field office says it is looking into the incident.
Reality
- Evidence58
- Adoption60
- Hype gap+14
- Incentives70
- Confidence54
The infrared and ultraviolet captures a bank reads to prove a license is genuine were reportedly on sale beside the ordinary scans, which leaves the cheapest step in account opening deciding nothing on its own.
Reality
- Evidence57
- Adoption62
- Hype gap+12
- Incentives72
- Confidence52
Earlier coverage
- Credit unions call AI model risk critical at a third the national-bank rate
Invest · September 2, 2026 · 1 publisher
- Six to nine vendors, five obligations each: the first AI security exercise is arithmetic
Build · August 26, 2026 · 1 publisher
- 88 breaches, 2.15 billion records, and 41 leaks that nobody can reset
Security · August 26, 2026 · 1 publisher
- CareCloud's breach count grew almost 11x, five months after the first filing
Security · August 21, 2026 · 1 publisher
- CareCloud's Breach Went From 350,000 to 3.7 Million, and the State Filings Still Say 350,000
Security · August 19, 2026 · 3 publishers
- One vendor, 19 million patients: the MyDr breach is a lesson in whose perimeter matters
Security · August 18, 2026 · 1 publisher
- NYDFS says a vendor's flaw reached its banks, and there is no regulator for the vendor
Invest · August 17, 2026 · 1 publisher
- A North Korean IT worker got hired by a federal agency. Vetting is a security control now.
Security · August 14, 2026 · 1 publisher
- Eight warehouses down, six brands notifying: the Ceva outage nobody's plan modelled
Security · August 14, 2026 · 2 publishers