Date |
Org/Sector |
Incident/Impact |
URL |
| 02/09/25 | Cloudflare (Tech / SaaS) | Supply chain attack via Salesloft / Drift; API tokens exfiltrated, support data exposed. | https://www.bleepingcomputer.com/news/security/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/ |
| 03/09/25 | Tesco / VMware / Computacenter (Retail / Tech) | Tesco sues over VMware support contract; cites security/service failures. | https://www.theregister.com/2025/09/03/tesco_sues_vmware_broadcom_computacenter/ |
| 05/09/25 | Wealthsimple (Finance) | Personal data stolen; <1% of clients affected; no funds lost. | https://www.bleepingcomputer.com/news/security/financial-services-firm-wealthsimple-discloses-data-breach/ |
| 05/09/25 | UK Schools / Intradev (Education) | Breach of supplier Intradev; schools warn of staff/pupil data exposure. | https://www.theregister.com/2025/09/05/uk_schools_intradev_breach/ |
| 08/09/25 | npm (Open source / Software) | Supply chain attack; hijacked npm packages with 2B weekly downloads injected with malware. | https://www.bleepingcomputer.com/news/security/hackers-hijack-npm-packages-with-2-billion-weekly-downloads-in-supply-chain-attack/ |
| 08/09/25 | Plex (Streaming / Media) | Authentication data and hashed passwords stolen; password reset enforced. | https://www.bleepingcomputer.com/news/security/plex-tells-users-to-reset-passwords-after-new-data-breach/ |
| 10/09/25 | Jaguar Land Rover (Automotive) | Attackers stole ‘some data’ in incident causing outages. | https://www.bleepingcomputer.com/news/security/jaguar-land-rover-confirms-data-theft-after-recent-cyberattack/ |
| 10/09/25 | Plex (Streaming / Media) | Plex tells users to reset passwords after breach exposing authentication data; 25M urged to reset. | https://www.computing.co.uk/news/2025/security/streaming-service-suffers-data-breach |
| 11/09/25 | Panama Ministry of Economy & Finance (Government) | INC ransomware group claims 1.5TB stolen; emails and financial docs. | https://www.bleepingcomputer.com/news/security/panama-ministry-of-economy-discloses-breach-claimed-by-inc-ransomware/ |
| 11/09/25 | LNER (Transport) | Third party supplier breach exposed passenger contact info and journey history; no financial data. | https://www.computing.co.uk/news/2025/security/passenger-details-exposed-in-lner-data-breach |
| 15/09/2025 | FinWise Bank (Finance) | Insider breach by ex-employee; ~689,000 customers data accessed. | https://www.theregister.com/2025/09/15/finwise_insider_data_breach/ |
| 17/09/2025 | Insight Partners (VC / Finance) | Ransomware attack; personal, banking, tax, and partner info exfiltrated; 12,657 impacted. | https://www.bleepingcomputer.com/news/security/vc-giant-insight-partners-warns-thousands-after-ransomware-breach/ |
| 18/09/2025 | SonicWall (Cybersecurity) | Breach exposed firewall backup configurations; password reset ordered. | https://www.theregister.com/2025/09/18/sonicwall_breach/ |
| 18/09/2025 | Insight Partners (VC) | Confirmed >12,000 individuals data compromised in ransomware. | https://www.theregister.com/2025/09/18/vc_giant_insight_partners_confirms/ |
| 22/09/2025 | Stellantis (Automotive) | Third party provider breach; customer contact data accessed; no financial data. | https://www.bleepingcomputer.com/news/security/automaker-giant-stellantis-confirms-data-breach-after-salesforce-hack/ |
| 23/09/2025 | DCS (EV Charging) | Supplier breach exposed customer names/emails; billing unaffected. | https://www.theregister.com/2025/09/23/dcs_data_breach/ |
| 23/09/2025 | Boyd Gaming (Gaming / Hospitality) | Attackers accessed employee and limited personal data. | https://www.bleepingcomputer.com/news/security/boyd-gaming-discloses-data-breach-after-suffering-a-cyberattack/ |
| 24/09/2025 | Collins Aerospace / UK & EU Airports (Aviation) | Ransomware disrupted airport IT at Heathrow, Berlin, Brussels; NCA arrest made. | https://www.theregister.com/2025/09/24/uk_agency_makes_arrest_in/ |
| 24/09/2025 | Collins Aerospace / Major EU Airports (Aviation) | Ransomware on Collins Aerospace MUSE disrupted check-in bag drop at Heathrow, Berlin, Brussels; lingering delays. | https://www.computing.co.uk/news/2025/security/european-travellers-face-long-delays-after-cyber-attack |
| 25/09/2025 | US Federal Agencies / Cisco Devices | CISA ordered urgent patching after Cisco zero days exploited in wild. | https://www.bleepingcomputer.com/news/security/cisa-orders-agencies-to-patch-cisco-flaws-exploited-in-zero-day-attacks/ |
| 25/09/2025 | Cooperative Group (Retail / Multi) | Hack cost ~£80m; data of 6.5m members compromised. | https://www.theregister.com/2025/09/25/empty_shelves_empty_coffers_coop/ |
| 25/09/2025 | Nurseries | Hackers reportedly steal pictures of 8,000 children | https://www.theguardian.com/technology/2025/sep/25/cybercriminals-steal-pictures-and-details-of-8000-children-from-nursery-chain |
| 26/09/2025 | Fortra / GoAnywhere MFT (Software/ Infrastructure) | Zero day CVE 2025‚ 10035 exploited; remote code execution and backdoors. | https://www.bleepingcomputer.com/news/security/maximum-severity-goanywhere-mft-flaw-exploited-as-zero-day/ |
| 29/09/2025 | Harrods (Retail) | 430,000 customers data stolen via supplier; names and contacts; no payment info. | https://www.theregister.com/2025/09/29/harrods_blames_thirdparty_supplier_after/ |
See how we can build your digital capability,
call us on +44(0)845 226 3351 or send us an email…
-
1 July 2026
Building a Foundation for Risk
-
22 June 2026
The Convergence Imperative
-
4 June 2026
From Reactive to Resilient: Managed Splunk Operations for a Leading UK Financial Business


