This Fortnight in Cyber Incidents October 15th 2025

Date range: 2nd October 2025 to 15th October 2025

A crisp round up of the most significant breaches and security incidents reported in the last 14 days. What happened, why it matters, and what to do next.

F5 confirms nation state breach; CISA issues emergency directive

What happened: Cybersecurity vendor F5 disclosed that a state linked actor infiltrated its systems, stealing BIG IP source code and undisclosed vulnerability details. The US cyber authority warned of imminent risk to federal networks using affected F5 products and ordered agencies to mitigate or disconnect impacted systems. Patches and guidance have now been released.

Why it matters: A rare vendor side compromise with potential downstream exploitation. If you run BIG IP or BIG IQ, patch immediately, rotate credentials and API keys, and review management plane access and logs.

UK: Capita fined £14 million over 2023 ransomware breach

What happened: The UK data protection regulator levied a £14 million fine on Capita for failures tied to its 2023 attack, citing delayed isolation of a compromised device and extensive data exfiltration.

Why it matters: Clear regulatory signal. Slow containment and weak controls now carry eight figure penalties. Expect boards to revisit incident response service levels and resourcing.

UK nurseries case: arrests following ransomware targeting children’s data

What happened: The Metropolitan Police arrested two suspects following the London nurseries ransomware case where criminals stole children’s personal data and contacted parents directly. Investigations continue.

Why it matters: Horrific targeting of sensitive data. Schools and childcare providers should minimise stored images and identity documents, tighten supplier access, and prepare parent facing communications playbooks.

Asahi (Japan): ransomware disrupts operations and delays results

What happened: Beverage company Asahi postponed quarterly results after a late September cyberattack disrupted breweries and business systems. The Qilin group claimed responsibility. Operational restoration is ongoing.

Why it matters: Another reminder that an IT compromise can halt production. Network segmentation between operational technology and information technology, offline backups, and tested continuity plans are essential.

Qantas: stolen customer data released months after breach

What happened: Qantas confirmed that data stolen in July has now been published by criminals. More than a million customers had contact and personal details exposed, with additional millions affected by limited data exposure.

Why it matters: Data leak extortion timelines can stretch for months. Prepare for long tail fraud and phishing as well as customer support surges well after initial containment.

Discord: third party breach exposes identity documents and partial payment data

What happened: Attackers compromised a customer support provider for Discord, exposing some users’ personally identifiable information, including identity documents, and partial payment data.

Why it matters: Supplier breaches continue to hit high profile platforms. Review vendor due diligence, data minimisation, and the off boarding of support exports.

Oracle warns of extortion against E Business Suite customers

What happened: Oracle reported that threat actors are attempting to extort customers, likely by exploiting known vulnerabilities. Customers are urged to patch immediately.

Why it matters: A classic pay or leak and encrypt play aimed at enterprise resource planning platforms. Prioritise patching internet facing ERP and enforce multi factor authentication on administration interfaces.

Trends we are seeing

  • Vendor and supply chain risk is front and centre. F5 and Discord show how upstream compromise can cascade downstream.
  • Regulators are tightening enforcement. The Capita penalty underscores that weak response leads to real financial pain.
  • Operational disruption still bites. Asahi demonstrates the exposure of manufacturing to IT outages.

What to do this week

  • If you run F5 BIG IP or BIG IQ: apply the latest updates, rotate secrets, restrict management interfaces, and hunt for indicators using vendor and authority guidance.
  • Tighten supplier controls: limit data shared with support providers, enforce short retention and encryption at rest, and require clear breach notification obligations in contracts.
  • Prepare long tail communications: keep templates ready for phased disclosures, covering initial breach notifications and later data release updates.
  • Board level hygiene: run a tabletop exercise focused on the first 24 to 72 hours of a breach, covering isolation speed, legal and regulatory steps, and customer messaging.

Enquire with us to better protect your organisation and avoid headlines. We will help you reduce vendor risk, harden identity and access, and build incident readiness that actually works.

USEFUL LINKS
SERVICES
CONTACT US