Security Report – 2 Oct 2026

Human error

Security Report – 2 Oct 2026

There is a version of cybersecurity that works perfectly. Employees recognise every phishing email, budgets stretch to cover every risk and the right person is always available when an alert comes in. That version exists in strategy decks and vendor pitches. It doesn’t exist on a Friday afternoon when someone in accounts payable has just wired money to the wrong person or reset their password to “Password123.” Most security programs are built for the first version. Most security teams are living in the second. People remain one of the hardest parts of security to control. That concern comes through clearly in the data: 68% of respondents identified human error as a potential gateway to a successful attack, making it the threat vector they were most concerned about.

The same pattern appears when we look at the organisations that experienced an incident. Four of the five leading contributing factors involved people. Poor user practices or human error ranked first at 41%, which can mean something as simple as trusting a phishing email, using weak passwords or sharing information with the wrong person. A lack of end-user cybersecurity training followed closely at 40%, suggesting that people may not always know how to recognise a threat, handle sensitive information or respond when something looks suspicious.

Recent Breaches

United States – FBI –Government & Public Sector

Exploit: Hacking

Risk to Business: Moderate: The FBI reportedly declared a “major incident” and notified its agents and support staff after a cyberattack on its job application portal FBIJobs.gov. Last week, the ShinyHunters ransomware group claimed it breached the FBI’s job application portal and stole data on thousands of agents and applicants. The FBI has since issued an internal notification to staff confirming that names, addresses, job titles and Social Security numbers were exposed in the incident. Unusually, the hackers are not seeking a financial ransom but are instead demanding the correction of an earlier FBI-issued report that they claim misrepresents their activities. The attack is the latest in a growing pattern of cyberattacks targeting U.S. federal agencies. The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a separate data breach only last month.

Asia & Pacific –Bitget – Finance 

Exploit: Third-Party Data Breach

Risk to Business: Moderate: Cryptocurrency exchange Bitget confirmed that attackers stole approximately $388 million after exploiting a vulnerability in a third-party security product used by the exchange. On September 24, Bitget noticed unauthorised transfers from some of its wallets and temporarily suspended customer withdrawals while it investigated. The stolen funds came from a portion of the exchange’s hot and warm wallets, with cold wallets remaining unaffected. While most customer funds are kept in offline cold wallets, hot and warm wallets are used to process withdrawals, with transfers still requiring approval before they are signed. Bitget has not disclosed exactly how the attacker gained initial access, but the investigation found that the attacker compromised a critical backend system within its wallet infrastructure and spoofed transaction data to trigger the approval process.

Talk to a TCT team member today about automation for your business.