Skip to content
HackInvasionCybersecurity Knowledge Hub

Daily Cyber Threat Brief — September 23, 2026: CTOS Digital Confirms Consumer Data Breach

️ CASE FILE — September 23, 2026

Lead story: CTOS Digital (Malaysia) confirms unauthorized access to its consumer-business environment — consumer data files accessed.

Also covered: BigCommerce / Ribon supply-chain breach (merchant customer data stolen) · Ransomware leak-site claims: Universal Auto Group, VIT India, Sherman Chan DDS, AFRICA-TECH.

Sources: 6 linked at the end of this brief.

Today's top stories

Today's brief leads with a confirmed breach at a Malaysian credit reporting agency — the kind of target where the stolen data is the product. Plus: a supply-chain breach hitting BigCommerce merchants through a compromised third-party app key, and a fresh batch of ransomware leak-site claims from four groups across four countries.



CTOS Digital confirms consumer data breach

Malaysian credit reporting agency CTOS Digital Bhd disclosed on September 23 that its cybersecurity systems detected unauthorized access to an environment supporting its consumer business. The company's forensic investigation found that certain data files containing a limited subset of processed consumer information were accessed.

What CTOS has confirmed so far:

  • The incident is contained to the identified environment; other systems remain secure and operational.
  • An independent incident response team was engaged for a full forensic investigation.
  • A subset of credit reporting services is temporarily unavailable while remediation is completed.
  • Relevant authorities have been notified; the company says it expects no material financial impact.

What remains undisclosed: the number of consumers affected and the specific categories of data accessed. For a credit bureau, those two blanks are the whole story — watch for the follow-up filing.

 Investigation notes — defender takeaway (click to expand)

Credit bureaus are concentration risk: one environment holds identity data worth more on the fraud market than almost any other vertical's PII. Segment consumer-data stores aggressively, and treat "limited subset accessed" disclosures as the floor, not the ceiling, until the forensic scope is finalized. Detection worked here — the gap to close is dwell time between first access and containment, which the filing does not yet state.

BigCommerce merchants hit via compromised Ribon app key

E-commerce platform BigCommerce has confirmed a supply-chain breach: between September 13 and September 17, attackers used a compromised application key belonging to Ribon and Ribon 1.5 — third-party storefront apps operated by Be A Part Of, a Fastr company — to pull customer data from merchant stores and inject malicious scripts into a small number of storefronts.

Stolen data includes customer names, email addresses, phone numbers, and shipping addresses. BigCommerce says account passwords and payment card data were held separately and were not affected. The key was revoked on September 17; BigCommerce uninstalled the apps from affected stores and began notifying merchants on September 18.

UK spirits retailer Master of Malt is the only affected merchant to speak publicly so far; it has reported the incident to the UK Information Commissioner's Office and believes Ribon may have been installed on hundreds of stores — far beyond BigCommerce's "small number of storefronts" characterization. Total merchant and customer counts remain unconfirmed.


 Investigation notes — defender takeaway (click to expand)

This is the second BigCommerce third-party app compromise in two years (the 2024 ZAGG / FreshClick case), but the technique differs: this time the attackers read existing customer records through a trusted API key rather than skimming checkout data. Audit third-party app permissions the way you audit service accounts — least privilege, key rotation, and anomaly detection on API call volume. A key working "page by page" through customer records for four days should have tripped a rate/volume alert.

Ransomware leak-site watch

Fresh claims surfaced on ransomware leak sites on September 22. These are claims, not confirmed breaches:

  • Universal Auto Group (US) — claimed by settra; thousands of documents allegedly stolen, operations reportedly affected.
  • Vellore Institute of Technology (VIT) (India) — claimed by AuditTeam.
  • Sherman Chan, DDS, Inc. (US) — claimed by Titan.
  • AFRICA-TECH (IT services, Mali) — claimed by N0n.
 Investigation notes — defender takeaway (click to expand)

Leak-site listings are early warning, not incident confirmation. Use them to check your exposure to the named groups' TTPs and to watch for your own organization appearing — but do not report them as breaches until the victim or investigators verify. Note the sector spread here: auto retail, education, healthcare, and IT services across four countries in a single day.

Incident timeline

Sept 13Attackers begin abusing the compromised Ribon app key against BigCommerce merchant storefronts.
Sept 16Ribon developers become aware the key is being misused (per Master of Malt's write-up).
Sept 17BigCommerce confirms the compromise, revokes the key, and uninstalls the Ribon apps from affected stores.
Sept 18BigCommerce begins notifying affected merchants; Master of Malt files with the UK ICO.
Sept 22Ransomware leak-site claims surface: settra / Universal Auto Group, AuditTeam / VIT, Titan / Sherman Chan DDS, N0n / AFRICA-TECH.
Sept 23CTOS Digital discloses consumer-data access in a Bursa Malaysia filing; forensic investigation continues.

Sources


EmoticonEmoticon