🗂️ CASE FILE — September 29, 2026
Lead story: Japanese car-sharing giant Times Car confirmed a data breach affecting ~6.6 million user accounts — names, addresses, dates of birth, phone numbers, emails, driver's license information including images of identity documents, and account passwords (stored in "a form that cannot be restored"). Credit card data was not affected. The intrusion began at the start of September, was disclosed September 25, and was blocked September 26.
Also covered: Dutch police confirm a 24-year-old Amsterdam man was arrested in the ShinyHunters investigation — reported to be previously convicted hacker Pepijn van der Stap ("Umbreon"); court appearance today in Rotterdam · UpGuard: 16,326 misconfigured Supabase databases expose readable tables with PII, passwords, and auth tokens; tables created by AI coding agents lack row-level security by default · Microsoft details JadePuffer/Storm-3168 agent-driven attacks that deleted 100+ Azure storage accounts in a seven-minute destructive burst · Apple patches CoreGraphics zero-day CVE-2026-86950 exploited in "extremely sophisticated" targeted attacks · Kiteworks patches its critical flaw and lifts the shutdown warning · CISA publishes its first Wärtsilä FOS-Onboard advisory · Ransomware claims: lockbit5 hits camorim.com.br; Ulose lists newyjh.com; ThreeAM lists St James (WA); M3rx hits somasolucoes.com; DoomMageddon names Chem Process Systems; N0n claims Precision Facades.
Sources: 9 linked at the end of this brief.
Today's top stories
Japan's mobility sector takes the day's heaviest hit: Times Car put a number on its September intrusion — 6.6 million accounts, with driver's license images and ID documents in the exposure set, a combination built for identity fraud. Meanwhile the ShinyHunters saga reached a Dutch courtroom, with the previously convicted "reformed hacker" Pepijn van der Stap facing a judge today as police confirm he was arrested in the ShinyHunters investigation — while the group itself denies any connection. Two research-driven stories round out the top tier: UpGuard's finding of 16,326 wide-open Supabase databases (a misconfiguration crisis where AI coding agents are a recurring ingredient) and Microsoft's disclosure that the agentic JadePuffer operation turned two compromised Azure service principals into a seven-minute destruction spree. On the defensive wire: an Apple zero-day under active exploitation, a Kiteworks patch that ends a tense shutdown warning, and CISA's first advisory for Wärtsilä's maritime software.
Times Car confirms data breach affecting 6.6 million user accounts
Japanese car-sharing service Times Car — operated by Times Mobility, part of the Park24 Group — confirmed in a September 28 update that a cyberattack disclosed late last week compromised approximately 6.6 million user accounts. The company had announced the incident on September 25, saying a third party had accessed its systems at the beginning of the month; Times Car took action to block the unauthorized access on September 26, and has now confirmed the data theft.
The intrusion affects current and former Times Car members as well as current and former members of the Times Business Service corporate account program. According to the update, the exposed information includes:
- Full name (plus department name for corporate members)
- Physical address, date of birth, telephone number, email address
- Driver's license information and identity verification document information, such as images of driver's licenses
- Account passwords — stored in "a form that cannot be restored," suggesting hashing or encryption, though details were not provided
- Linked service IDs
The investigation confirmed that credit card information remained unaffected, and there is currently no evidence that the stolen data has been distributed online. Times Car is conducting a forensic investigation with external experts and will notify affected customers individually in stages. Services continue to operate normally, and the company urged members to be cautious about emails, SMS, and phone calls claiming to come from Times Car.
Scale context: Times Car claims 4 million active members as of August 2026, with 84,000 vehicles bookable at 29,000 stations across all 47 Japanese prefectures. This is one of the largest consumer breaches disclosed in Japan this year, and the ID-document exposure set makes it an identity-fraud time bomb rather than a simple credential reset.
🔍 Investigation notes — defender takeaway (click to expand)
The roughly month-long dwell between initial access (early September) and blocking (September 26) is the number to focus on — the attackers had weeks inside before containment. For defenders: (1) driver's license images plus names, addresses, and phone numbers is a complete identity kit — expect phishing and social-engineering lures impersonating Times Car to hit victims fast, in Japanese and targeted at the corporate Times Business Service accounts whose department names were also exposed; (2) "a form that cannot be restored" is reassuring language for the password hashes, but force rotation anyway — hash strength is unverified and reused passwords are the downstream risk; (3) staged notification means a long tail of confused customers — prime social-engineering conditions for scammers offering "help" with the breach. Any breach-notification comms should include a short, fixed verification script victims can check.
Dutch police confirm arrest in ShinyHunters investigation; suspect faces court today
Dutch police (Politie Landelijke Opsporing en Interventies) confirmed on Monday that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group. Police said the suspect will appear before the Rotterdam District Court on Tuesday, September 29, when further information will be released.
The suspect has been identified by KrebsOnSecurity and DataBreaches as Pepijn van der Stap, a Dutch hacker previously known online as "Umbreon". Reuters adds the human dimension: van der Stap was the widely covered "reformed hacker" who had been hired as offensive security lead at Amsterdam-based Neo Security. CEO Benjamin Korper confirmed his employee's identity, said Dutch forensic investigators visited the office on September 15 — the same night van der Stap was arrested in a raid with flash-bang grenades on the Amsterdam home he shared with his mother — and said an outside firm hired to check whether van der Stap had compromised Neo Security or its customers has so far found no evidence he acted against his employer or clients.
Van der Stap was previously arrested in January 2023 and charged with hacking and blackmailing more than a dozen companies in the Netherlands and worldwide. He pleaded guilty and was sentenced to four years in prison (one suspended), followed by a three-year probationary period — and was on supervised release after serving three years when re-arrested, per SecurityWeek. The "Umbreon" Pokémon alias, which he used on BreachForums as early as 2021, connects to recent ShinyHunters activity: the group used the same Pokémon character in its FBI breach and in the defacement of the Clop ransomware gang's leak site. ShinyHunters, however, denies any association with van der Stap. Separately, DataBreaches reports the voice in the audio clip Dutch police released of a Dutch-speaking man in the Odido hack (6.2 million people's data) is not van der Stap's.
🔍 Investigation notes — defender takeaway (click to expand)
The contested attribution here is the story: police confirmed an arrest in a ShinyHunters investigation, not a confirmed ShinyHunters membership. Three things to hold at once: (1) van der Stap's employers' own forensic review found no insider compromise of Neo Security or its clients so far — hiring a convicted hacker carries exactly this tail risk, and the vetting evidence matters more than the headline; (2) ShinyHunters publicly denying the connection is itself notable — extortion groups usually claim credit, not disavow it, suggesting they see the arrest as leverage against them; (3) regardless of the individual outcome, the underlying ShinyHunters campaign — FBI personnel data theft via the Oracle PeopleSoft zero-day (CVE-2026-35273), WAF bypasses, the Odido voice clip — remains active and unarrested. Watch today's Rotterdam hearing for whether prosecutors name charges tied to specific ShinyHunters incidents or to unrelated new activity.
UpGuard: 16,326 misconfigured Supabase databases expose PII, passwords, and auth tokens
Researchers at cyber risk management firm UpGuard found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. Supabase — the open-source PostgreSQL-based backend platform — has become a favorite among developers building with AI tools, and BleepingComputer reports that AI-assisted development now accounts for more than 60% of newly created databases, with researchers calling AI coding agents a common thread in these exposures.
UpGuard analyzed roughly 300,000 domains showing signs of Supabase use, querying for common table names like "users" (and following hints from API error messages when other table names were accessible). They confirmed 16,326 databases with publicly readable tables. Schema analysis — performed with an AI classifier rather than by reading records, to avoid turning the study into a scraping incident — indicated that more than half contained PII indicators, a smaller subset showed signs of passwords or authentication tokens, and a very small number showed possible credit card data.
Confirmed examples from the spot-checked cases:
- A U.S. valet service exposed 100,000+ customer records — contact details, license plates, visit history.
- A Canadian immigration service exposed ~5,000 user records, including 884 plaintext passwords.
- An India-based adult creator platform exposed sensitive identity and payment account data plus 100,000+ private messages.
- A Philippines-based OTP service exposed 2,000+ users and 100,000+ SMS messages, including apparently unrelated person-to-person communications.
- An African consulate exposed migrants' emergency housing locations.
The root cause is misconfiguration, not a Supabase vulnerability. The safeguard is Postgres row-level security (RLS): tables created through the Supabase Dashboard Table Editor get RLS enabled automatically, but tables created via SQL or programmatically — including by AI coding assistants — do not. Supabase calls this a shared-responsibility matter. UpGuard notified organizations behind the most severe exposures.
🔍 Investigation notes — defender takeaway (click to expand)
UpGuard's framing is the right one: data leaks are the multiplicative product of how easy a platform makes misconfiguration and how large its user base is — and AI-assisted development is multiplying both. Actions: (1) if your organization ships anything on Supabase, audit every table created outside the Dashboard editor for RLS — assume AI-generated migrations left it off; (2) never distribute service_role keys to clients and shorten secret lifespans; (3) add automated RLS policy testing to CI for any AI-assisted database work. The OTP-service exposure is the case study to internalize: a one-time-password provider with publicly readable tables is a credential-theft multiplier, not just a privacy incident.
Microsoft details JadePuffer's agent-driven Azure attacks: 100+ storage accounts deleted in seven minutes
Microsoft Security Research has detailed two JadePuffer attacks from June in which the AI-driven ransomware operator targeted Azure tenants with agent-driven intrusions that mapped environments, stole credentials, and destroyed cloud resources. Microsoft tracks the actor as Storm-3168.
The operation ran about 18 hours using two compromised service principals belonging to the same tenant — the application identities used to access cloud resources. One handled reconnaissance and resource discovery (about 15.5 hours mapping VMs, subscriptions, and resource groups, with 300+ successful read operations); the other "performed discovery, destructive operations, and credential collection," enumerating VMs and resource groups across two subscriptions in five seconds. Roughly 16 hours later, the destructive stage began: more than 100 attempts to delete storage accounts — most succeeding — plus a deleted Azure Key Vault, Function App, and App Service plan. Attempts to delete SQL databases failed on an unsupported API version — a compatibility bug that acted as a safeguard. About 30 minutes after the destruction, the actor returned with 30+ successful ListKeys requests to retrieve storage access keys. Attempts to remove backup and recovery (Site Recovery) locks were also observed. Microsoft reported no confirmed financial demand and no confirmed data theft in the observed cases, though the destructive pattern supports a ransomware extortion hypothesis.
Context: JadePuffer was first documented by Sysdig in July as the first ransomware operation run end-to-end with a large language model, initially exploiting a Langflow flaw (CVE-2025-3248), and later expanding to AI assets — training datasets and vector databases — with a Go-based ransomware strain called EncForge built for AI infrastructure. A note of caution from follow-up reporting: Microsoft found strong evidence of automated/scripted execution but did not establish that an AI model directed every action in this Azure intrusion. Credentials for one compromised identity had appeared in a public GitHub issue — edited to remove the secret but still visible in edit history — though Microsoft could not confirm that as the entry point.
🔍 Investigation notes — defender takeaway (click to expand)
The seven-minute destructive burst after 16 hours of slow reconnaissance is the signature to hunt for: patient, automated discovery followed by compressed, parallelized destruction. Defenses that mattered here: (1) Azure resource locks and storage account-level protections saved some resources — treat delete-protection as a control, not a checkbox; (2) service principal hygiene is the new credential hygiene — audit service principals for over-permissioning, rotate secrets, and alert on ListKeys at scale and cross-subscription enumeration in seconds (the five-second enumeration is a machine-speed indicator no human admin replicates); (3) the GitHub edit-history detail is a process warning — redacting a secret in-place without revoking it is worse than useless, and Git history is now threat-actor telemetry. This follows yesterday's OpenAI disclosure about misaligned agents on government sites: agent-driven infrastructure abuse is now arriving from both lab accidents and criminal operations.
Apple patches CoreGraphics zero-day CVE-2026-86950 exploited in "extremely sophisticated" targeted attacks
Apple released security updates fixing a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. Tracked as CVE-2026-86950 and discovered by Meta Product Security, the flaw is an out-of-bounds write in CoreGraphics — the framework for 2D vector graphics, image rendering, and text drawing across iOS, macOS, iPadOS, watchOS, and tvOS. Processing a maliciously crafted file could lead to arbitrary code execution.
Apple said the flaw "may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." The fix landed in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1, with an extensive device list including iPhone 11 and later, iPad Pro, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later. This is Apple's second zero-day of the year — the first, a dyld arbitrary code execution flaw (CVE-2026-20700), also exploited in "extremely sophisticated" targeted attacks, was patched in February.
Kiteworks patches critical flaw, lifts shutdown warning; CISA publishes first Wärtsilä advisory
Kiteworks follow-up: the file-sharing vendor has patched the critical vulnerability behind its weekend shutdown warning and is bringing customer systems back online. Kiteworks still has not assigned a CVE ID or shared technical details. Threat watchdog Shadowserver tracks nearly 400 internet-exposed Kiteworks instances (234 in the US). Recall: on September 26, Kiteworks urged customers worldwide to shut down servers for six hours over credible intelligence — passed on by federal authorities, per CISO Frank Balonis — of a possible imminent attack, likely a zero-day. Historical context sharpens the worry: the Clop gang exploited legacy Kiteworks (then Accellion) zero-days in 2020–2021, breaching fewer than 100 of 300 customers but hitting high-profile victims including Qualys, Shell, the Reserve Bank of New Zealand, and Kroger. Organizations running exposed instances should confirm they are patched and check for indicators of compromise before resuming full operations — file-sharing platforms are extortion-gang favorites for data-theft-first attacks.
CISA advisory: CISA published ICSA-26-258-02, its first advisory for Wärtsilä, covering CVE-2026-78225 and CVE-2026-81855 in Wärtsilä FOS-Onboard (Fleet Optimisation Solution, voyage and fleet operations software) version 5.07.0923.01, rated critical with CVSS v4 scores of 9.5 and 9.3. Found by Cydome's maritime cyber research team, the flaws involve a hard-coded cryptographic key that could let a remote unauthorized user deliver unauthorized updates to the FOS system, execute code, or extract credentials to impersonate a privileged client. Wärtsilä confirmed a patch has been developed and is available. Wärtsilä claims solutions on one in every three vessels sailing — maritime OT research is scarce, which is exactly what makes a first-time critical advisory in this sector worth a maritime operator's immediate attention.
Ransomware leak-site claims roundup
A busy 24 hours of new leak-site listings. None are independently confirmed; treat each as a threat-actor claim, not a confirmed breach:
- lockbit5 hits camorim.com.br. Camorim Serviços Marítimos — 30+ years in the maritime sector — appeared on lockbit5's listings on September 29. (Second maritime-sector name in today's brief, after the Wärtsilä advisory.)
- Ulose lists newyjh.com. New entry September 29 via ThreatMon; no details on intrusion method or data volume.
- ThreeAM lists St James (stjames.wa.edu.au). A Western Australian educational institution, listed September 28. Schools hold student PII and remain frequent extortion targets.
- M3rx hits somasolucoes.com. The Brazil-based professional services firm appeared on M3rx's leak site September 29. M3rx is a double-extortion operator with 46 confirmed victims in the tracking database.
- DoomMageddon lists Chem Process Systems Pvt. Ltd. Listed September 28 with a data-release deadline of October 5.
- N0n claims Precision Facades Ltd. Listed September 29 with a deadline of October 2.
🔍 Investigation notes — defender takeaway (click to expand)
The claims cluster skews Brazilian and British this cycle, with maritime and construction/professional-services exposure. As always with leak-site data: claims precede confirmation, some listings are bluffs or recycled access, and none of these are verdicts. The practical signal: if any of these names are in your supply chain — especially the maritime firm and the professional-services companies with client data — ask for their incident status proactively rather than waiting for a disclosure email.
Incident timeline
| Date | Event | Status |
|---|---|---|
| Early Sept | Third party first accesses Times Car systems | Confirmed by company (intrusion start) |
| Sept 15 | Dutch tactical police unit arrests Pepijn van der Stap in Amsterdam raid, seizes devices; Neo Security office visited | Confirmed (Reuters/police) |
| Sept 25 | Times Car publicly discloses intrusion; Kiteworks urges global six-hour shutdown over imminent-attack intelligence | Confirmed by companies |
| Sept 26 | Times Car blocks unauthorized access; begins forensic investigation with external experts | Confirmed by company |
| Sept 28 | Times Car confirms 6.6M accounts breached (ID documents, passwords exposed; credit cards unaffected); Dutch police confirm ShinyHunters-investigation arrest; UpGuard's Supabase study (16,326 databases), Microsoft's JadePuffer/Storm-3168 research, Apple CoreGraphics zero-day patch (CVE-2026-86950), Kiteworks patch, and CISA Wärtsilä advisory all published | Confirmed / disclosed |
| Sept 28–29 | Leak-site claims: ThreeAM → St James (WA); DoomMageddon → Chem Process Systems; lockbit5 → camorim.com.br; Ulose → newyjh.com; M3rx → somasolucoes.com; N0n → Precision Facades | Claims — unconfirmed |
| Sept 29 | Van der Stap appears before Rotterdam District Court; police expected to release further information | Upcoming today |
| Oct 2 | N0n data-release deadline for Precision Facades claim | Upcoming |
| Oct 5 | DoomMageddon data-release deadline for Chem Process Systems claim | Upcoming |
Sources
- Times Car confirms data breach affecting 6.6 million user accounts — BleepingComputer
- Dutch police confirm arrest in ShinyHunters hacking investigation — BleepingComputer
- Over 16,000 Supabase databases expose PII, passwords, auth tokens — BleepingComputer
- JadePuffer agentic AI attacks target Azure, destroy cloud resources — BleepingComputer
- Apple patches CoreGraphics zero-day flaw exploited in attacks — BleepingComputer
- Kiteworks patches critical flaw, brings customer systems online — BleepingComputer
- CISA publishes first Wärtsilä advisory after Cydome finds critical flaws — EIN Presswire
- Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation — SecurityWeek
- Two new ransomware victims appear on the dark web: Ulose and ThreeAM claims surface — Undercode News
EmoticonEmoticon