Cyber Breaches & Enterprise Incidents – October 2025

 

Date

Source

Org/Sector

Incident/Impact

URL

10/2/25 BleepingComputer Red Hat (Tech/Software) GitLab instance breached; extortion group claims ~570GB stolen from 28,000 repos. https://www.bleepingcomputer.com/news/security/red-hat-confirms-security-incident-after-hackers-breach-gitlab-instance/
10/7/25 Guardian Kido Nurseries (Childcare) Attack on UK nursery chain; data of ~8,000 children stolen; 10 child profiles leaked. https://www.theguardian.com/uk-news/2025/oct/07/man-teenage-boy-arrested-kido-nurseries-cyber-attack-london
10/7/25 BleepingComputer Avnet (Electronics Distributor) Confirmed breach: 1.3TB compressed data stolen. https://www.bleepingcomputer.com/news/security/electronics-giant-avnet-confirms-breach-says-stolen-data-unreadable/
10/7/25 BleepingComputer Salesforce (SaaS / CRM) Confirmed large scale data theft attacks; company refused ransom demands. https://www.bleepingcomputer.com/news/security/salesforce-refuses-to-pay-ransom-over-widespread-data-theft-attacks/
10/8/25 BleepingComputer Discord (Social / Platform via Zendesk) Hackers claim breach affecting 55M users, ~70k government ID photos exposed. https://www.bleepingcomputer.com/news/security/hackers-claim-discord-breach-exposed-data-of-55-million-users/
10/12/25 Times of India Qantas Airways (Airline) Hackers released data from July breach: >1m sensitive records, 4m names/emails. https://timesofindia.indiatimes.com/technology/tech-news/qantas-customer-data-released-by-hackers-after-july-breach-says-airline/articleshow/124498443.cms
10/14/25 BleepingComputer Mango (Retail / Fashion) Marketing vendor compromised; customer data exposed. https://www.bleepingcomputer.com/news/security/clothing-giant-mango-discloses-data-breach-exposing-customer-info/
10/15/25 Financial Times Capita (Outsourcing) ICO fines Capita £14m for breach impacting >6m people (2023 incident disclosed Oct 2025). https://www.ft.com/content/25741917-e42c-494f-8b47-6f1a37eec805
10/15/25 BleepingComputer F5 Networks (Cybersecurity Vendor) Hackers stole BIG IP source code and undisclosed vulnerabilities. https://www.bleepingcomputer.com/news/security/hackers-breach-f5-to-steal-undisclosed-big-ip-flaws-source-code/
10/15/25 The Register F5 Networks (Cybersecurity) Nation state linked attackers breached F5, stole source code/vulnerabilities. https://www.theregister.com/2025/10/15/highly_sophisticated_government_hackers_breached/
10/15/25 Reuters F5 Networks (Cybersecurity) US based F5 breach attributed to state sponsored attackers (suspected China). https://www.reuters.com/technology/breach-us-based-cybersecurity-provider-f5-blamed-china-bloomberg-news-reports-2025-10-16/
10/16/25 BleepingComputer Prosper (Fintech / Lending) Data breach exposed ~17.6M accounts; personal data leaked to Have I Been Pwned. https://www.bleepingcomputer.com/news/security/have-i-been-pwned-warns-of-prosper-data-breach-impacting-176-million-accounts/
10/17/25 Reuters Envoy Air (Airline) Targeted extortion attack exploiting Oracle EBS vulnerabilities; business data accessed. https://www.reuters.com/sustainability/boards-policy-regulation/envoy-air-targeted-oracle-linked-hacking-campaign-2025-10-17/
10/23/25 BleepingComputer Toys R Us Canada (Retail) Customer data stolen and leaked online. https://www.bleepingcomputer.com/news/security/toys-r-us-canada-warns-customers-info-leaked-in-data-breach/
10/27/25 The Register Ravin Academy (Education / Iran) Student & staff data compromised (names, phones, usernames). https://www.theregister.com/2025/10/27/breach_iran_ravin_academy/
10/27/25 Checkpoint Research Askul (Japan / Ecommerce Retail) Ransomware disrupted ecommerce ops; potential customer data leak. https://research.checkpoint.com/2025/27th-october-threat-intelligence-report/

See how we can build your digital capability,
call us on +44(0)845 226 3351 or send us an email…