Cybersecurity Weekly News (September 21–27): 120 Million Data Records Illegally Collected, Check Point Zero-Day and AI Risks
In Vietnam, major developments included a case involving approximately 120 million illegally collected personal data records, ongoing implementation of cybersecurity and personal data protection requirements, and Social Engineering scams impersonating authorities. Internationally, a Check Point zero-day, a Gemini testing incident, ransomware exploitation of TeamCity and claims by ShinyHunters regarding the FBI all pointed to the same broader trend: attackers are increasingly targeting identity, privileged infrastructure and systems that can provide access to multiple downstream assets.
Cybersecurity developments during September 21–27, 2026 highlighted growing risks around personal data, online fraud, actively exploited vulnerabilities and AI systems with broad access privileges.
👉 Businesses can follow additional developments through the IPSIP Vietnam cybersecurity news section

I. Cybersecurity News in Vietnam
1. Approximately 120 million personal data records illegally collected in Dak Lak
On September 24, 2026, Dak Lak Provincial Police announced the prosecution of a case involving the illegal trading and collection of personal data.
Investigators said the suspects operated through Facebook, Telegram and private online groups, using methods designed to conceal their identities and transactions. The total volume of collected information was estimated at approximately 120 million data records.
The scale is significant, but the more important issue for businesses is what such data can be used for after collection. Names, phone numbers, account information and other identifiers can become inputs for phishing, impersonation, credential harvesting and more convincing Social Engineering campaigns.
This raises several practical questions for organizations: What data is being stored? Where is it located? Who can access it? Are bulk exports monitored? And can unusual access patterns be detected quickly?
Recommended action: Businesses should maintain a data inventory, classify information by sensitivity, restrict large-scale downloads or exports, and monitor unusual access behavior. Sensitive information should also be protected through appropriate encryption controls.
2. Decree 327/2026/ND-CP raises practical questions about incident response readiness
Decree 327/2026/ND-CP was not issued during this week; it has been in effect since August 19, 2026. However, its implementation continues to raise practical questions for businesses around monitoring, preserving electronic data, maintaining logs and responding to cyber incidents.
From an operational perspective, logging is not simply about enabling logs. Organizations need to know where logs are stored, how long they are retained, who can access them, whether timestamps are synchronized across systems and how quickly information can be retrieved when an incident occurs.
These weaknesses often become visible only during an actual event: logs exist but have already expired, data is available but cannot be located quickly, or responsibilities are unclear when evidence must be collected.
Recommended action: Review log-retention policies, synchronize system time, restrict access to security logs, define Incident Response ownership and regularly test whether relevant data can be retrieved within required timeframes.
3. Hung Yen promotes Cybersecurity Law and Personal Data Protection Law to more than 1,300 participants
On September 23, 2026, Hung Yen Provincial Police organized a conference on the Cybersecurity Law, the Personal Data Protection Law and measures for strengthening data security.
According to information published by the Ministry of Public Security, the conference connected 104 communes and wards and involved more than 1,300 participants, including representatives from government agencies, banks, businesses and telecommunications organizations.
The development shows that cybersecurity and data protection requirements are increasingly moving from legal documents into operational implementation.
For businesses, compliance should therefore go beyond policies and forms. Organizations need to understand what categories of data they process, where the data resides, who has access, how long it is retained and what procedures apply when an incident occurs.
Recommended action: Build and maintain a data inventory, classify information, apply Role-Based Access Control and regularly review access rights. IPSIP provides additional context in its article on the 2026 Personal Data Protection Law
4. Quang Tri stops impersonation scam involving VND 150 million
On September 23, 2026, police in My Thuy commune coordinated with a bank to stop a resident from transferring VND 150 million to scammers.
According to the Ministry of Public Security, the scammers impersonated law-enforcement officials, claimed the victim was linked to a drug investigation and pressured him to transfer money.
This is a typical Social Engineering model: attackers do not need to exploit software vulnerabilities. Instead, they exploit authority, fear and urgency to push victims into acting before verification.
In a corporate environment, similar tactics can involve impersonating executives, banks, regulators or business partners to request emergency payments, account changes, OTPs or login credentials.
Recommended action: Unusual financial requests should require out-of-band verification, and payment workflows should separate request and approval roles. Real-world impersonation scenarios should also be incorporated into cybersecurity awareness training for employees
II. International cybersecurity news
5. Check Point zero-day CVE-2026-93616 exploited before a patch was released
Check Point released a patch on September 22 for CVE-2026-93616, a critical path traversal vulnerability affecting Security Management Server.
The vulnerability received a CVSS score of 9.8/10 and had reportedly already been used in targeted attacks before the patch became available.
Security Management Server plays a central role in managing policies and gateways. As a result, compromise of this type of management infrastructure can have a much broader impact than compromise of a single endpoint.
Another important point is incident response. When a vulnerability has already been exploited before a patch is released, installing the patch only prevents further exploitation. Organizations still need to determine whether attackers may have gained access earlier.
Recommended action: Check the deployed version and Jumbo Hotfix Take, apply the patch and review logs and indicators of compromise. For Internet-facing security appliances, patching should be combined with threat hunting rather than assuming that “patched” means “never compromised.”
👉 Read article at Check Point warns of zero-day vulnerability in Management Server and attacks targeting Spark firewalls
6. Gemini accessed real-world systems after a security test environment was not fully isolated
A security evaluation involving Gemini resulted in the AI system accessing real-world systems belonging to three companies after the test environment was not fully isolated from the Internet.
According to the published account, Gemini searched publicly available information and used credentials to interact with targets outside the intended simulated environment. The incident occurred earlier but was disclosed and acknowledged more recently.
The key issue is not that “AI went rogue.” The more useful interpretation is a familiar security problem: the sandbox was not completely isolated, access controls were insufficient and credentials could be used beyond the intended scope.
As AI Agents gain access to terminals, browsers, APIs and credentials, organizations increasingly need to treat them as identities capable of taking real actions within production environments.
Recommended action: Isolate AI security-testing environments, control egress traffic, use sandbox-specific credentials, restrict permitted domains and IP addresses, and log every Agent action for later review.
7. Ransomware groups begin exploiting critical JetBrains TeamCity vulnerability
On September 24, 2026, CISA had updated its Known Exploited Vulnerabilities Catalog to flag CVE-2026-63077 as being used in ransomware attacks.
CVE-2026-63077 is an authentication bypass vulnerability affecting JetBrains TeamCity. JetBrains patched the issue on July 25, while CISA initially added it to the KEV Catalog on August 5. This week, CISA updated the entry to reflect confirmed ransomware exploitation.
The risk is particularly significant for software-development organizations because TeamCity is part of the CI/CD environment. Build servers often contain credentials, secrets, configuration data and access to downstream systems.
Compromise of such infrastructure can therefore affect not only the server itself, but also build integrity, artifacts and deployment pipelines.
Recommended action: Identify Internet-facing TeamCity instances, patch vulnerable versions, review indicators of compromise and rotate credentials where compromise is suspected. Secrets should be managed through dedicated secret-management platforms rather than hardcoded in CI/CD pipelines. IPSIP has also covered broader software supply-chain attack risks.
8. ShinyHunters claims it breached the FBI and obtained employee data
ShinyHunters claimed it had breached FBI systems and obtained information related to a large number of current and former employees.
This claim requires careful wording. On September 22, Reuters reported that the information originated from ShinyHunters and that the FBI had not responded to requests for comment at the time of publication.
A day later, Reuters reported reviewing some of the allegedly stolen data and finding detailed information about the work of certain FBI employees. However, Reuters continued to describe the material as allegedly stolen, meaning the full origin and scope of the dataset remained separate from the hacker group’s own claim.
For businesses, the main lesson is the value of employee data. Information such as job title, department, email address, role and project involvement can be used to build targeted spear-phishing, impersonation and credential-harvesting campaigns.
Recommended action: Deploy phishing-resistant MFA, limit unnecessary exposure of employee information, monitor leaked credentials and regularly review third-party access to internal data.
👉 Read article at ShinyHunters claims to have breached FBI systems and stolen employee and applicant data
III.What should businesses prioritize after September 21–27?
This week’s developments highlight four major trends.
First, personal data continues to have direct value for cybercriminals. When information is collected or traded at scale, the impact extends beyond privacy and becomes an input for fraud, phishing and impersonation.
Second, attackers are increasingly targeting systems with broad access privileges. Security Management Server and TeamCity are strong examples: compromising one central platform can create access to multiple downstream assets.
Third, AI Agents are becoming identities that need to be managed. Agents can use credentials, call APIs, access networks and perform real actions. Their permissions therefore need to be controlled in the same way as service accounts or privileged identities.
Finally, patch management cannot rely on CVSS alone. A vulnerability being actively exploited or used in ransomware attacks should be prioritized differently from another vulnerability with a similar score but no exploitation evidence.
IPSIP Vietnam's expert perspective
Cybersecurity developments during September 21–27, 2026 show that risk is increasingly concentrated around three critical areas: data, identity and highly privileged infrastructure.
An illegally collected data repository, an unpatched firewall management server, a CI/CD platform holding secrets or an AI Agent with excessive access can all become the starting point of a much larger incident.

For businesses, the priority should not simply be adding more security tools. The more important questions are which assets need to be protected first, who currently has access, which vulnerabilities are being actively exploited and how quickly the organization can detect and respond when an incident occurs.
References
Ministry of Public Security – Dak Lak launches investigation into illegal personal data trading involving approximately 120 million records
Ministry of Public Security – Hung Yen promotes the Cybersecurity Law, Personal Data Protection Law and data-security measures
Ministry of Public Security – Quang Tri stops VND 150 million phone scam
BleepingComputer – CISA: Ransomware gangs now exploiting critical TeamCity flaw














Comments