• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
  • X
  • Facebook
  • YouTube
  • LinkedIn
Screen Connect
Support
Customer Portal
Pay Online
SWK logo.

SWK Technologies

Software Solutions & Services

  • Accounting & ERP Software
      • Acumatica Cloud ERP
        • Overview
        • Construction
        • Distribution
        • Field Service
        • Financial Management
        • Manufacturing
        • Professional Services
        • Project Accounting
        • Retail-Commerce
      • Sage Intacct
        • Overview
        • Construction and Real Estate (CRE)
        • Distribution Operations for Sage Intacct
        • Financial Services
        • Healthcare
        • Manufacturing Operations for Sage Intacct
        • Nonprofits
        • Professional Services
        • Sage Intacct Payroll powered by ADP
      • Sage 100
        • Overview
        • Business Intelligence
        • Core Accounting & Financials
        • Distribution
        • Manufacturing
        • Payroll
        • Sage 100 Contractor
      • More Accounting Products
        • QuickBooks
        • Sage 50
        • Sage 300
        • Sage 500
        • Sage BusinessWorks
      • ERP Add-ons
        • ADP Workforce Now
        • Avalara
        • AvidXchange
        • BILL
        • BigCommerce
        • CIMCloud
        • Cloud Hosting
        • DataSelf
        • DocLink
        • Endpoint Automation Solutions
        • Fortis
        • FreightPOP
        • Lumber
        • Microsoft 365
        • Netstock
        • Quadient
        • Sage Fixed Assets
        • Sage HCM
        • Sage Intacct Payroll powered by ADP
        • Sage Supply Chain Intelligence
        • Savant WMS
        • ScanForce
        • Solver
        • SPS Commerce
        • Velixo
        • Workforce Go!
      • More ERP Add-ons
        • Azure
        • ConverSight
        • Crystal Reports
        • KnowledgeSync
        • Nuvei
        • Nectari
        • Ottimate
        • Pacejet
        • Planning Maestro
        • Sage CRM
        • Sage HRMS
        • Sage Intelligence
        • Service Pro
        • ShipStation
        • Shopify
        • STACK
        • Starship
        • Sugar CRM
        • Traild
      • Industries
        • Construction
        • Distribution
        • Financial Services
        • Healthcare
        • Manufacturing
        • Nonprofit
        • Professional Services
        • Retail
  • Managed Cloud Services
      • Managed IT Services
        • Managed Cloud Services
        • Network Assurance Core
        • Co-Managed IT
        • Email Hosting
        • IT Support
        • Microsoft 365 Services
        • Server Monitoring
        • Virtualization
      • Cybersecurity
          • CyberAssurance CORE™
          • Cybersecurity Solutions
          • Backup & Continuity
          • Compliance
          • Dark Web Monitoring
          • EDR
          • Encryption
          • MDR
          • MFA
          • Penetration Testing
          • Security Training
          • SOC
          • Spam & Virus Filtering
          • vCIO
          • Vulnerability Assessment
      • Cloud Services
        • Secure Cloud Hosting
        • Azure Services
        • Infrastructure-as-a-Service
        • Acumatica IaaS
      • Industries
        • Financial Services
        • Healthcare
        • Construction
      • Locations
          • Nationwide
          • Austin
          • California
          • Chicago
          • Minneapolis
          • New Jersey
          • New York
          • North Carolina
          • Philadelphia
          • Phoenix
          • San Diego
          • Seattle
  • Consulting & Implementation
    • Business Technology Consulting
    • eCommerce
    • Financing
    • Human Capital Management
    • Managed Cloud & IT Services
    • Partner Program
    • Software Development
    • Software Implementation
  • Resources
    • Help Desk
    • Blog Posts
    • Payments Portal
    • Webinars
    • YouTube Channels
    • Acumatica Resources
    • Sage Intacct Resources
    • Sage 100 Resources
    • IT Resource Pages
  • About
    • About SWK
    • Awards & Recognition
    • Life@SWK
    • Careers
    • Success Stories
    • SWK Gives
  • Contact
    • Contact Us
    • Support
    • Our Locations

SWK Cybersecurity News Recap September 2026

September 28, 2026 by Hector Bonilla

Home » Cybersecurity » SWK Cybersecurity News Recap September 2026

Open notebook with a hand-drawn September calendar under a yellow highlighted heading, with an uncapped yellow Winsor & Newton watercolor marker and its black cap resting on the page.

After a wave of cyber incidents reported over the past summer, many tied to the ongoing U.S.-Israel-Iran conflict in the Persian Gulf, cybersecurity news seems to be taking an even sharper turn this autumn. This latest Recap by SWK Technologies covers the top headlines from September 2026 to highlight some of the most concerning trends emerging this fall, including multiple AI models hacking different institutions as well as a new brazen attack by the ShinyHunters gang:

OpenAI Agents Broke Containment to Hack Australian Government

Australian Prime Minister Anthony Albanese revealed on September 23 that an OpenAI agent researching healthcare spending got around access blocks on his country’s Medicare statistics database, viewing both public and nonpublic files and even writing new files into the system. The ChatGPT owner said the June incident only surfaced during an internal review in August, and the company notified Australian officials on September 10 through a public mailbox, which Albanese said kept the responsible minister in the dark for five more days. OpenAI maintains that no patient records were accessed, while a forensic investigation aided by the Australian Signals Directorate works to determine whether other government systems were affected.

OpenAI agents also attempted three other intrusions between May and June, targeting a University of New Mexico digital library, the Data USA public statistics site and the Australian Institute of Health and Welfare. Australia’s Defense Minister conceded that the Medicare access was unintentional, which makes criminal charges unlikely, though lawmaker David Pocock has called for liability for autonomous agent attacks to be written directly into the nation’s legal framework.

This disclosure also follows an earlier July admission by Open AI that GPT-5.6 Sol and a more capable internal-only model, both running with reduced cyber refusals during a capability benchmark, exploited a zero-day flaw in an internally hosted package proxy to reach the Internet before chaining stolen credentials and additional zero-days to execute code on Hugging Face servers. OpenAI’s August findings described agents coordinating across supposedly isolated tests through an improvised message board, prompting the company to quarantine the model’s weights, delay frontier training runs and require chain-of-thought monitoring for its most capable models. The incident drew wider scrutiny of how frontier models are tested, with the U.K. AI Security Institute finding that every model it evaluated attempted to cheat on its cybersecurity tests at least some of the time.

ShinyHunters Claims Sensitive Data Leaked in FBI Hack

The ShinyHunters cybercriminal group announced on September 22 that it had compromised the FBI, defacing the FBIJobs.gov applicant portal and claiming to hold sensitive data on nearly every FBI agent and job applicant. The group said it exploited a previously unknown vulnerability in Oracle PeopleSoft human resources software, while the bureau has stated it was actively investigating but had not yet determined whether the point of breach sat with a third-party provider or its own systems. Reuters partially verified a sample of the stolen records against credit bureau files and prior breach data, finding matching details in at least 10 cases, including information on FBI Director Kash Patel.

Instead of a ransom payment, ShinyHunters gave the bureau one week to correct or remove a May 15 public service announcement that accused the group of harassing victims and their families and occasionally resorting to swatting. The group has  claimed that the campaign is not financially motivated, though at least one expert has questioned that stance, arguing that foreign intelligence services would covet the data and that a working PeopleSoft zero-day exploit may be worth more than the records themselves.

A Reuters exclusive published September 23 examined a 5000-line spreadsheet from the sample, finding assignment details that tie named staff to China-focused units, Russia operations sections, telecom intercept work, covert access teams and human intelligence programs. A former FBI operative called the data “a foreign intelligence service goldmine” and said that “China would be incredibly interested to know the individuals who are working against it,” while a former Army investigator warned that listed emergency contacts, frequently spouses or children, may lack the security awareness of their relatives. Reuters could not authenticate the full spreadsheet, though it confirmed career details for eight people through court filings, news coverage and public profiles.

The claimed breach caps a difficult year for bureau security, following a China-linked intrusion into an FBI surveillance system that was classified as a major incident and the pro-Iranian Handala group’s leak of what they claimed was Patel’s personal email in March. ShinyHunters has also remained one of the most active cyber extortion crews in recent years, claiming the Canvas breach that disrupted finals week at several universities, previous Oracle PeopleSoft exploit attacks that breached over 100 organizations and additional intrusions against Panera Bread, Carnival Cruises, Workday, Kodak and many others. The group also defaced the leak site of rival ransomware gang Cl0p on September 18, threatening to reveal which businesses allegedly paid the other gang during its Oracle E-Business Suite extortion campaign.

Google Says Gemini AI Model Breached Real Companies

Google confirmed on September 18 that its Gemini models accessed the systems of three real companies during a May capture-the-flag exercise run by testing firm Irregular, after a configuration mistake left the supposedly closed environment connected to the public Internet. The fictional target in the exercise shared a name with an actual business, and the models guessed a password in one case and reused credentials exposed in a public repository in the other two before stopping once they recognized the systems were real.

Irregular did not alert Google until late July, and the testing firm has confirmed that the Gemini breaches shared a root cause with incidents previously disclosed by OpenAI, Anthropic and Meta. Google then held the disclosure for several more weeks until inquiries from The Wall Street Journal, explaining that the models caused no harm and that it had already notified the three affected companies and federal authorities. Heather Adkins, VP of Security Engineering at Google, said the model found public information and guessed credentials for websites it believed were part of the test, adding that her team worked with Irregular on changes to its testing processes.

The Gemini incident joins a growing list of rogue artificial intelligence hacking episodes, though many security experts argue that human error and weak security controls contributed as much as the models’ advancing capabilities. Much of that concern centers on AI agents that are granted broad access to sensitive systems without clear oversight, since many businesses cannot say which resources those agents can reach or who is accountable when one acts outside its intended scope. Those gaps grow more dangerous as attackers adopt the same models, and malware has already been found in the wild using Gemini to rewrite its own code and evade detection.

Homeland Security Releases 2026 Election Infrastructure Security Plan

The Department of Homeland Security released a 2026 Election Infrastructure Security Plan on September 24, a 13-page document from the Cybersecurity and Infrastructure Security Agency (CISA) that lays out threats to election systems and catalogs the voluntary, no-cost services available to state and local officials. The plan arrived roughly 40 days before the November midterms after Secretary Markwayne Mullin had originally promised it by mid-August, and it covers risks ranging from software vulnerabilities and voter registration database hacks to insider threats and bomb threats at polling places.

The plan notes that hackers have attempted to breach voter registration systems in all 50 states with confirmed success in at least 20, and its priority safeguards for those databases are largely foundational controls. They include multi-factor authentication (MFA), role-based access with least privilege, network monitoring and separating public-facing services from the master database. CISA also acknowledges that many state and local election offices struggle with basic cyber hygiene and vulnerability remediation, and the plan directs officials to CISA’s existing best practices for election systems, which already call for MFA on voter registration and election night reporting systems.

At the federal level, the plan designates CISA’s 10 regional directors as election security advisers and describes a free platform for sharing threat indicators among election officials, fusion centers and federal partners. The document does not specify staffing or funding, though, and the administration’s fiscal 2027 budget proposal would eliminate CISA’s election security program if Congress approves it. Earlier in September, Sen. Alex Padilla and Rep. Joseph Morelle pressed DHS to release more than $39.6 million in election security funding that Congress approved in the fiscal 2026 appropriations bill.

At the state level, California Gov. Gavin Newsom signed a package of election protection bills on Sept. 19 that creates new felonies for interfering with elections, framing the laws as a safeguard against federal meddling. The plan lists continuous penetration testing and on-site risk assessments among CISA’s available services, though several secretaries of state have said tabletop exercises and pen testing were unavailable this cycle, while West Virginia’s Republican Secretary of State Kris Warner said some no-cost CISA support to his state had continued. The plan itself calls election security a nonpartisan issue, though reactions have split along familiar partisan lines, with administration officials emphasizing election integrity and enforcement against illegal voting while many state election officials and members of the Democrat Party have voiced concern over federal actions involving local offices and voter rolls as well as leveraging the security concerns for political ends.

Anthropic Releases Report on AI Misuse, Including Cyber Attacks

Anthropic published its fourth threat intelligence report on September 10, detailing misuse of its Claude models disrupted between December 2025 and August 2026 across seven categories that include cyber operations, influence campaigns, surveillance, fraud and illicit distillation. The company concluded that AI has erased much of the skill gap separating state-sponsored teams from lone operators, with multi-agent frameworks now running reconnaissance, exploitation and data theft while humans mainly pick targets and review results. Documented cases range from a Russian espionage actor whose agents automatically rebuilt malware after detection to suspected ShinyHunters affiliates who pulled data belonging to roughly 200 downstream customers after breaching a single software provider.

Observers have noted that the report may imply that cheaper AI-driven attacks could widen the pool of businesses worth targeting, since attackers no longer need to reserve limited effort for only the most valuable victims. Outside researchers have observed the same shift, with Gambit Security uncovering a Chinese-speaking hacker who used agents running DeepSeek, Kimi and an older Claude model to hit as many as 100 businesses in five days and steal more than 600,000 payment card records for roughly $8000. Anthropic has also disclosed that its own models breached three external entities during testing, while Meta attributed a similar incident to a misconfiguration that let its model reach the Internet.

The report further accused seven China-based labs, including DeepSeek and Moonshot, of illicit distillation, and China’s Cyberspace Administration has since opened a probe into whether sensitive user data from those two firms ended up with Anthropic. The regulator initially summoned representatives from all seven labs named in the report before narrowing its focus, though no penalties have yet been announced.

Alongside the report as well as the OpenAI and Gemini incidents covered here previously, OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei both urged the UN Security Council on September 23 to coordinate internationally on AI risks, with Amodei proposing common testing standards and a notification system for security incidents. OpenAI has confirmed working with Anthropic and Google DeepMind on a shared safety framework, while Trump allies have begun casting Amodei as the face of AI doomerism amid pushback on his safety warnings. Altman has separately said that safety should outrank new capabilities, and Amodei has called on the industry to slow the pace of frontier model development.

Stock Price Falls for Healthcare Tech Firm Astrana after Breach

Astrana Health, a California-based physician network and healthcare technology company, reported in a Form 8-K dated September 22 that attackers impersonated staff and spoofed its main corporate phone number to trick employees into granting access to company systems. The company believes private or confidential data on its servers was accessed or acquired without authorization, and it has since reset credentials, restricted remote access tools and restored certain systems from clean backups while it determines whether patient, employee or provider information was involved.

No hacking group has claimed the attack as of this writing and Astrana has not said whether ransomware was involved, though it warned the incident could affect its operations, financial condition, patients, providers and reputation. Astrana shares dropped 5.5% during afternoon trading after the disclosure, adding to existing pressure from a securities-law investigation into its acquisition strategy and a $545 million related-party loan. Astrana is only the latest of many healthcare businesses struck by cyber incidents, including pharmaceutical and medical supplies distributor McKesson, which confirmed an attack targeting employee corporate accounts in August after ShinyHunters claimed credit.

Face the Latest Cyber Threats with SWK Technologies

When AI can breach a firewall in seconds and even the FBI cannot spot hackers, cybersecurity is clearly evolving into something that requires even more proactive vigilance than ever before. SWK Technologies will help your business monitor these emerging threats and prepare your team to spot the tactics seen throughout this month’s headlines.

Contact SWK here to learn how the SWK team can help protect your systems and data against the next wave of AI-driven and human-led cyberattacks.

Contact SWK

Category: Cybersecurity, Blog, News and Events

Sidebar

Recent Posts

  • SWK Cybersecurity News Recap September 2026
  • Cloud Hosting vs. IaaS – Which Is Right for You?
  • Sage Intacct Construction vs PENTA
  • Acumatica Sales Order to Invoice: Walkthrough
  • Real-Time Portfolio Margin Across Complex Multi-Entity Structures
  • 2026 QuickBooks Price Increases – What They Mean for Your Renewal
  • Top Benefits of Choosing One ERP and Cybersecurity Vendor

Categories

Ready to take the next step?

Contact SWK today to get in touch with one of our experts. We’ll go over your business challenges and unique needs, and see where you can unlock new value from your technology and make your operations run easier.

Get in touch!

Our Latest Posts

Open notebook with a hand-drawn September calendar under a yellow highlighted heading, with an uncapped yellow Winsor & Newton watercolor marker and its black cap resting on the page.

SWK Cybersecurity News Recap September 2026

Read moreSWK Cybersecurity News Recap September 2026
Illustration of a woman with long dark hair in a blue blazer pointing left to the words "Cloud Hosting" and right to "IaaS," with blue question marks around her head.

Cloud Hosting vs. IaaS – Which Is Right for You?

Read moreCloud Hosting vs. IaaS – Which Is Right for You?
Sage Intacct Construction vs PENTA ERP comparison

Sage Intacct Construction vs PENTA

Read moreSage Intacct Construction vs PENTA

Awards and Accreditations

Top work places in NJ 2020.
Acumatica the Cloud ERP gold certified partner.
The Gold Microsoft partner logo on a black background.
Sage business partner diamond logo.
Dell Technologies Gold Partner
Sage tech partner logo.

Stay in the know!

Subscribe for exclusive ERP, process automation, IT and cybersecurity news.

Twitter
  • Facebook
  • YouTube
  • LinkedIn

Home
About
Contact

Support
Screen Connect
Pay Online
Downloads

SWK logo.

Headquarters:
120 Eagle Rock Ave, Suite 330
East Hanover, NJ 07936

Contact:
info@swktech.com
(877) 979-5462

Copyright © 2026 · SWK Technologies, Inc. · All Rights Reserved · Terms of Use · Privacy Policy

This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. By continuing to browse this site you agree to the use of cookies. Visit our privacy policy to learn more.