Security Report – 9 Oct 2026

Secure AI

Security Report – 9 Oct 2026

Generative AI tools like ChatGPT are becoming part of everyday business. Employees use them to draft emails, write documents, create presentations, and save valuable time. While the productivity benefits are significant, many organisations are adopting AI faster than they are implementing the policies and safeguards needed to use it safely.

The biggest risk comes from the information users enter into AI platforms. Employees may unknowingly paste confidential data such as client information, pricing, financial details, contracts, or internal business information into public AI tools. Once sensitive information leaves the organisation, there is a risk that the business loses control over where that data is stored, processed, or used.

Rather than banning AI, businesses should focus on managing it responsibly. This includes approving which AI platforms can be used, creating an AI Acceptable Use Policy, implementing Data Loss Prevention (DLP) controls within Microsoft 365, blocking unauthorised AI tools, and providing staff with practical training. With the right governance in place, businesses can safely benefit from AI while reducing the risk of exposing sensitive information.

Recent Breaches

United States – BigCommerce –Technology

Exploit: Supply Chain Attack

Risk to Business: Moderate: Ecommerce platform BigCommerce confirmed a supply-chain breach involving compromised credentials from third-party app Ribon, affecting multiple merchant customers. BigCommerce is a cloud-based SaaS ecommerce platform that businesses use to build and operate online stores without needing to develop their own commerce infrastructure. The company confirmed the credential compromise on September 17, stating that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by Be A Part Of, a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts. The UK-based online spirits vendor Master of Malt is among the BigCommerce customers that received breach notifications, with the retailer confirming that attackers accessed shopper information, including full names, email addresses, phone numbers and shipping postal addresses.

Asia & Pacific –Government Solution Service (GSS) – Government & Public Sector 

Exploit: Hacking

Risk to Business: Moderate: Japan’s digital agency disclosed a data breach affecting the personal information of approximately 240,000 individuals. In late June, hackers accessed files from Japan’s Government Solution Service (GSS) using a maintenance and operations employee’s account. A subsequent investigation determined in July that a vulnerability in a VPN product had been exploited to gain access. The attackers compromised over 246,000 records containing names, addresses, email addresses and phone numbers belonging to users, public officials, administrative staff and businesses and individuals working with GSS. The agency did not name the exploited VPN product but confirmed that the targeted vulnerability had already been publicly disclosed before the attack was detected. The agency said it would strengthen its vulnerability management practices in response.

Talk to a TCT team member today about automation for your business.