Cybercrime,
Fraud Management & Cybercrime,
Incident & Breach Response

ISMG routinely compiles updates on cybersecurity incidents and breaches occurring globally. This week: a collective call to action on cyber defense from OpenAI; the banning of Russian ChatGPT accounts; a critical Gitea vulnerability being exploited; the theft of data affecting nearly 9 million U.K. airport passengers; the discovery of five suspected North Korean remote workers; exposed data of Barcelona police; a DDoS attack impacting services in Norway; Taiwan’s legal actions against nine individuals for AI server exports; and Nigeria’s move toward establishing sovereign cloud services.
OpenAI Calls for ‘Collective Action’ on Cyber Defense
OpenAI, alongside several of its competitors and major corporations, has signed an open letter advocating for collaborative efforts in securing AI systems. This coalition has proposed three guiding principles aimed at enhancing collective cyber defense. These principles emphasize the need to acknowledge that existing security measures are insufficient, to empower defenders with advanced AI capabilities, and to initiate a unified response strategy.
The letter emphasizes, “Each of us can reduce risk now,” underscoring that a diverse range of stakeholders—including organizations, cybersecurity companies, technology partners, and governments—must play a crucial role in bolstering defenses, especially in critical infrastructure sectors that often suffer from budget constraints.
It also calls for concrete actions that are easier to articulate than to implement. Notably, it urges governments to enhance coordination of cyber defense efforts across local, national, and international landscapes. The coalition argues for making cyber defense a prominent leadership issue and elevating security standards, instructing organizations to address high-risk vulnerabilities while employing efficient, cost-effective models to achieve broader cybersecurity coverage.
Among the 116 signatories of this letter are influential players in the cybersecurity and networking fields, including Abnormal, Broadcom, Cisco, Cloudflare, Palo Alto Networks, Snyk, Tenable, and ZScaler, as well as tech giants AWS, Google, and Microsoft.
OpenAI Bans Russian ChatGPT Accounts
OpenAI has restricted several ChatGPT accounts that originated from Russia, following the identification of a group purporting to be based in Israel and calling itself the International Burke Institute. According to OpenAI, this group utilized ChatGPT by feeding it prompts in Russian to generate English-language comments for social media.
The banned accounts employed a VPN for access, given that ChatGPT is unavailable in Russia. The misuse of OpenAI’s technology contributed to the fabrication of misleading comments on platforms including Substack, Telegram, X, Facebook, and LinkedIn. These fake narratives were often tied to AI-generated articles that imitated legitimate academic works, accompanied by real identities and photos misused as authors. The posts frequently exhibited signs of machine translation from Slavic languages and directed audiences to a website associated with the International Burke Institute, registered in February 2025.
OpenAI assessed the overall influence of the group’s activities as limited, noting the low engagement their posts garnered on social media. However, the company highlighted the potential dangers of how malicious actors can leverage AI to create a façade of authenticity, manipulate narratives, and lay the groundwork for future propaganda efforts.
Critical Gitea Flaw Exploited
In a troubling development, attackers are exploiting a serious vulnerability identified in Gitea, an open-source Git hosting platform that allows unauthorized execution of commands on compromised servers, resulting in installations of miner-like payloads. This vulnerability, designated as CVE-2026-60004, has been rated 9.8 on the CVSS scale, indicating its severity. It enables attackers with write access to repositories to plant malicious Git hooks and execute shell commands with the same privileges held by the Gitea service account.
A specific incident was reported involving an exposed Gitea server that was exploited to run a dropper with cryptocurrency-mining capabilities. The malware sought out processes with high CPU usage, eliminated competition, downloaded an architecture-compatible payload, executed it, and subsequently erased the original dropper file. The precise details regarding the malicious actor behind this attack remain undisclosed.
Adding to the risk is Gitea’s default setting for open registration, which permits attackers to create accounts and repositories that grant them the write access necessary for exploitation. Organizations utilizing Gitea are urged to upgrade to version 1.27.1 or later and to disable open registration if it’s not essential.
Cyberattack Compromises Data of Nearly 9 Million Passengers at U.K. Airports
In a significant data breach, unknown cybercriminals accessed passenger information belonging to approximately 8.7 million individuals who traveled through Manchester, London Stansted, and East Midlands airports. This alarming revelation was made by the Manchester Airports Group, which disclosed that hackers targeted systems related to car park bookings, lounge access, and Wi-Fi sign-ups within the airports.
Despite the substantial number of passengers affected, the airport operator reported there was no operational disruption caused by the breach, and no banking details or payment card information was compromised. The breached data primarily comprised customers’ email addresses, phone numbers, vehicle registrations, and postcodes. Passengers are being warned to remain vigilant against potential follow-up phishing attempts in light of the breach.
Discovery of Five Suspected North Korean Remote Workers
Cybersecurity firm Huntress has revealed findings of five individuals suspected to be North Korean remote workers, engaged across various sectors including IT, healthcare, sales and marketing, and financial services. An investigation identified that these workers utilized fraudulent identities and documents, along with technology designed to obscure their actual locations or facilitate remote accesses.
One investigation highlighted three healthcare workers in Australia, all of whom connected through a VPN while exhibiting abnormal work patterns, with most of their activities occurring outside conventional business hours. Researchers uncovered apparent forged Chinese identity documents, suggesting an organized effort to deceive employers. Additionally, high-tech devices allowing for concealed remote operations were discovered in the possession of one employee.
Data Leak Exposes Barcelona Police Officers’ Information
A notable data leak has compromised sensitive data belonging to 568 officers of the Barcelona Urban Guard. Reports indicate that this information, including names, professional ID numbers, work locations, and shift schedules, is accessible online, raising serious security concerns as Catalonia remains on a Level 4 antiterrorism alert.
This incident comes at a precarious time, with the exposure potentially putting officers and their families at risk by disclosing their work routines. Political figures have publicly criticized the incident as a major security failure, asserting that this mishap demands urgent accountability from city officials. Authorities have indicated that while the data was part of transparency efforts, they will strive to remove the information from online availability.
DDoS Attack Disrupts Norwegian Government Services
Several governmental digital services in Norway experienced severe disruption due to a large-scale DDoS (Distributed Denial of Service) attack targeting IT provider Vivicta. Lasting approximately 30 hours, this assault affected a variety of essential services, including identity verification systems and public records access.
The critical ID-porten system, which serves about 4.5 million users, faced significant obstacles affecting authentication processes for numerous government services. Authorities recognized that this attack was notably larger than previous incidents affecting the same infrastructure.
Taiwan Charges Nine Individuals Over Illicit AI Server Exports
Taiwanese authorities have initiated legal proceedings against nine individuals—including an employee from Nvidia—charged with unlawfully exporting advanced AI servers to China, thus circumventing established export controls. Prosecutors detailed that 74 B300 servers had already been shipped successfully to mainland China, while another shipment was intercepted before reaching its destination.
This crackdown is symptomatic of escalating tensions in the U.S.-China tech rivalry, particularly concerning advanced AI technology. Complaints from prosecutors indicate that the actions taken by the defendants warrant maximum penalties, with some reportedly creating fictitious companies and fraudulent documents to evade detection.
Nigeria Pushes Forward on Sovereign Cloud Initiative
Nigeria has embarked on an ambitious project to establish sovereign data centers and enhance domestic cloud services, aiming to reduce dependence on international providers. The Nigerian government announced the formation of the Joint Technical Committee under the National Sovereign Cloud Initiative, which intends to bolster national cybersecurity through improved data control.
The initiative’s goals include promoting a cloud-first policy, establishing certification requirements for data security, and attracting significant investment to support these efforts. As stated by the NITDA director general, it is essential for the nation to take charge of its digital future.
Other Stories From Last Week
Reported by ISMG’s Emilia David in Manhattan and David Perera in Northern Virginia.

