Skip to content
HackInvasionCybersecurity Knowledge Hub

Daily Cyber Threat Brief — September 25, 2026: Bitget Loses $351.6M in Suspected North Korean Hack

🗂️ CASE FILE — September 25, 2026

Lead story: Bitget crypto exchange discloses a $351.6 million theft from its hot and warm wallets — the company links the attack to suspected North Korean hackers, has suspended withdrawals, and says customer losses will be covered by its $464M User Protection Fund.

Also covered: Malicious AI agents steal 600K+ credit cards from online retailers (Gambit Security) · CISA warns ransomware gangs are now exploiting the critical TeamCity flaw CVE-2026-63077 · ShinyHunters sets a one-week ultimatum in the FBI-breach claim · Ransomware claim wave: Akira, WallStreet, Krybit, Spirals, incransom name new victims.

Sources: 10 linked at the end of this brief.

Today's top stories

Today's brief leads with one of the largest crypto exchange heists of the year: Bitget says roughly $351.6 million was stolen from its hot and warm wallets, with the theft linked to suspected North Korean operators. Also today: a Gambit Security investigation shows autonomous AI agents did the heavy lifting in a campaign that stole more than 600,000 payment card records from online retailers at an average cost of $25 per target, CISA flags that ransomware gangs have added the TeamCity flaw CVE-2026-63077 to their arsenal, and a fresh wave of dark-web ransomware claims names victims across law, education, healthcare, and retail.

Hooded analyst seen from behind facing a wall of monitors displaying red and green cryptocurrency candlestick charts and network threat graphs in a dark operations room

Bitget discloses $351.6M theft from hot and warm wallets; North Korean hackers suspected

Cryptocurrency exchange Bitget has disclosed that suspected North Korean hackers stole approximately $351.6 million in assets from a limited number of its hot and warm wallets. Bitget says its security systems flagged multiple unauthorized transfers on Thursday evening, and all withdrawals are temporarily suspended while the company investigates with law enforcement agencies, on-chain security institutions, and cybersecurity experts from Mandiant and SlowMist.

The theft spanned seven chains — Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base — and hit multiple assets including ETH, XRP (the largest single-chain loss), BNB, AVAX, USDT, and USDC, according to CEO Gracy Chen. Some chains have already confirmed the attacker's wallet addresses have been frozen. Bitget has not yet explained how the attackers breached its key backend wallet-service system to forge transfer information and trigger the authorization-signing process. Cold wallets and the overwhelming majority of platform assets remain secure; the self-custodial Bitget Wallet runs on independent infrastructure and was not affected.

Crucially for customers: Bitget says the incident falls within the coverage of its User Protection Fund — currently holding 5,500 BTC worth roughly $464 million — which will cover all losses. Deposits and trading continue to operate normally.

🔍 Investigation notes — defender takeaway (click to expand)

The technical detail to watch is the attack path: forging transfer information inside the backend wallet-service system to trigger the signing flow. That is not a wallet compromise in the classic sense — it is a compromise of the authorization pipeline itself. For anyone operating signing infrastructure: treat the transaction-construction and approval service as your crown jewels, with hardware-backed signing, quorum approvals, and anomaly detection on transfer-request metadata, not just on destinations. And note the attribution framing: "suspected North Korean" groups have a documented playbook of high-value exchange heists; watch for laundering patterns across the named chains.

Malicious AI agents steal 600K+ credit cards from online retailers at ~$25 a target

Gambit Security has reconstructed a financially motivated campaign in which a Chinese-speaking operator used three open-source AI harnesses to breach online retailers and steal payment card data — with minimal human effort and trivial cost. The tools: Strix for vulnerability discovery, Cairn for autonomous exploitation, and Hermes as the campaign orchestrator with a "Red Team Operator" persona and 121 custom skills (78 offensive).

Between September 10 and 15, the operator launched at least 105 attack projects, compromising at least 27 companies to varying degrees — including a Fortune 500 hospitality company, a major US airline, a large US industrial supplies distributor, and an online fashion retailer. Gambit gained access to the attacker's staging server to reconstruct the operation: the operator issued just 1,951 short commands in Chinese across 260 sessions while the agents handled reconnaissance, exploitation, persistence, and cleanup independently, sometimes operating for hours without intervention. The haul: more than 600,000 unexpired payment card records stolen from two companies, with web skimmers confirmed on 19 websites and malicious scripts tied to 100+ additional sites. Average cost: $25.46 per target (range $3.13–$79.31); total campaign spend estimated at $12,000–$18,000. Some intrusions ended with destructive cleanup — data deletion after exfiltration — and at one US wine retailer a cron job persistently re-infected files every two minutes after cleanup.

Magnifying lens over swirling blue data streams and red circuit-board traces with a robotic arm silhouette, symbolizing autonomous AI-driven payment-card theft in a dark digital scene

🔍 Investigation notes — defender takeaway (click to expand)

The economics are the headline: a single operator compromised 27 companies with $12–18K of AI model spend. Your defenses must assume agent-scale automation, not human-scale attackers. Harden the exact choke points this campaign used: audit checkout-page JavaScript and tag managers for skimmer injections, watch AWS S3 content and databases for poisoned objects, check for rogue cron jobs re-infecting cleaned files, and review misconfigured sudo rules and exposed AWS credentials. One documented intrusion chained an unauthenticated SQL injection into MFA bypass, admin access, file upload, privilege escalation, AWS Secrets Manager extraction, and a Magento database — patch the chain, not just one link.

CISA: ransomware gangs now exploiting critical TeamCity flaw CVE-2026-63077

On Wednesday, CISA updated its Known Exploited Vulnerabilities catalog to flag that ransomware gangs are now actively exploiting CVE-2026-63077, a critical authentication bypass in JetBrains TeamCity On-Premises. An unauthenticated attacker with HTTP(S) access can abuse the TeamCity agent polling protocol to bypass authentication entirely and execute arbitrary OS commands with the privileges of the TeamCity server process (CVSS 9.8).

JetBrains patched the flaw on July 25 in versions 2025.11.7 and 2026.1.3; CISA added it to KEV on August 5 with a three-day federal remediation deadline; JetBrains confirmed in-the-wild exploitation on August 7 and shared IoCs. This is the fourth TeamCity issue since October 2023 to be tagged as exploited in the wild and subsequently abused in ransomware campaigns. Shadowserver is currently tracking just over 160 TeamCity servers that remain unpatched. Related: JetBrains previously disclosed that its own Cadence cloud service was breached via this flaw (discovered August 23), with attackers extracting AWS credentials — Cadence users were urged to revoke and rotate everything.

🔍 Investigation notes — defender takeaway (click to expand)

Build servers are ransomware gold: they hold signing keys, cloud credentials, and the pipeline that turns source code into shipped software — a compromise can poison every downstream build. Patching alone is not enough on this one: BreachLock and SafeBreach researchers advise treating unpatched-and-exposed instances as an active-compromise scenario — patch, rotate all credentials and tokens issued during the exposure window, and review build logs for unexpected artifacts or config changes. Then take the server off the open internet entirely; it has no business being there.

ShinyHunters sets one-week ultimatum in FBI-breach claim

The ShinyHunters group continues to press its claim of breaching FBI systems via an Oracle PeopleSoft zero-day, now demanding the FBI retract a May 2026 FBI report about the group within one week — explicitly framing the operation as "not financially motivated." The group claims 2–3 TB of employee and applicant data; Reuters and 404 Media partially matched portions of a ~5,000-record sample against external records but could not confirm the data came from FBI systems. The FBI still has not confirmed a breach and says it is investigating; FBIjobs.gov and the Special Agent applicant portal remain offline. The PeopleSoft flaw is now being tracked as CVE-2026-35273 per some reports, and the campaign reportedly extends to 100+ organizations hit since June 2026.

🔍 Investigation notes — defender takeaway (click to expand)

Still a claim, not a confirmed incident — but the ultimatum clock is now a forcing function: watch for a data dump or escalation within the week if the FBI does not comply. Regardless of the FBI angle, the PeopleSoft exposure path is real and already weaponized at scale since June: audit your internet-facing PeopleSoft deployments and confirm you are on current CPU levels, because the same flaw is reportedly being used against other organizations right now.

Ransomware watch: fresh claim wave names law, education, healthcare victims

Dark-web monitoring for September 24 logged a cluster of new ransomware victim claims — all unverified allegations at this stage:

  • Akira names Strack Companies (ThreatMon monitoring).
  • WallStreet adds a US law firm (Prater & Ridley Attorneys At Law) and the Catholic University of El Salvador.
  • Krybit claims Jones the Grocer, Air Tanzania, and efada.sa (Saudi Arabia).
  • Spirals hits Uganda's Armada Credit Bureau; incransom lists welgenone.com, a US healthcare/wellness provider.

A law firm, a university, a hospital-adjacent provider, and a national airline — the claim set is a reminder that ransomware listing is cheap for operators and expensive for victims to disprove. Monitor for official confirmations before treating any as a breach.

🔍 Investigation notes — defender takeaway (click to expand)

Treat every entry as alleged until the victim confirms. But do not wait for confirmation to hunt: if you share a sector with a named victim, sweep for the named actors' known IoCs and TTPs now. The law-firm listing is the highest-stakes one — a confirmed compromise there would expose client confidences, not just corporate data — and law firms historically underinvest in detection relative to their data's value.

Incident timeline

July 2026AI-agent card-theft campaign active (per Gambit); JetBrains patches TeamCity CVE-2026-63077 (July 25).
Aug 5–7CISA adds CVE-2026-63077 to KEV; JetBrains confirms in-the-wild exploitation and shares IoCs.
Aug 23JetBrains discovers its own Cadence environment was breached via the TeamCity flaw; AWS credentials extracted.
Sept 10–15105 attack projects launched in the AI-agent retail campaign; 27+ companies compromised.
Sept 21–22ShinyHunters claims FBI breach via PeopleSoft zero-day; Gambit publishes its AI-agent campaign report (Tuesday).
Sept 23CISA warns ransomware gangs are now exploiting CVE-2026-63077; FBI reiterates it is investigating the ShinyHunters claims.
Sept 24Ransomware claim wave: Akira (Strack Companies), WallStreet (Prater & Ridley, Catholic University of El Salvador), Krybit (Jones the Grocer, Air Tanzania, efada.sa), Spirals (Armada Credit Bureau), incransom (welgenone.com). Bitget discovers unauthorized transfers Thursday evening.
Sept 25Bitget discloses the $351.6M theft, links it to suspected North Korean hackers, and suspends withdrawals.

Sources


EmoticonEmoticon