This Fortnight in Cyber Incidents September 17th 2025

Date Range: 3rd September to 17th September 2025

Here’s your round-up of the biggest breaches and security incidents reported in the last 14 days

Jaguar Land Rover: production still halted, data confirmed affected

JLR has extended its production shutdown into late September following the early September attack. The company now says some data was affected, while a controlled restart is planned. Suppliers and retailers report knock on disruption.

Why it matters: A major UK manufacturer experiencing sustained downtime shows how quickly an IT compromise can halt real world production and harm the wider supply chain.

LNER (UK rail): customer contact details exposed via a supplier

LNER warned customers after unauthorised access at a supplier exposed contact information and some journey history. Ticketing and rail operations were not affected and no passwords or payment data were involved.

Why it matters: Supplier breaches continue to hit essential transport services. Expect phishing attempts that exploit exposed contact details.

Plex (streaming): password resets after account data theft

Plex disclosed a breach involving emails, usernames, hashed passwords and authentication data. Customers were instructed to reset passwords and enable two factor authentication.

Why it matters: Even with hashed passwords, credential reuse can cascade into corporate compromise if staff recycle passwords across systems.

Wealthsimple (fintech): supply chain compromise affects up to about 30,000

Wealthsimple reported that a third party software package was compromised, exposing personal data for fewer than one percent of customers. Accounts and funds were not accessed. Impacted users were offered monitoring.

Why it matters: Another example of a supplier issue creating a wide blast radius in financial services.

Panama Ministry of Economy and Finance: ransomware group claims large data theft

Panama’s ministry disclosed a workstation-level incident. The INC Ransom group claimed extensive data exfiltration and posted samples.

Why it matters: Government ministries remain high-value targets. Claims of large scale exfiltration raise fraud and diplomatic-risk concerns.

Nevada state government (update): recovery after August attack

Following an August ransomware incident that shut state websites and services, officials say most public-facing sites are back online, with investigations and hardening continuing.

Why it matters: This shows the multiweek recovery curve for large public-sector estates. Services can return before the underlying risks are fully addressed.

Chess.com: 4,541 users’ data exposed via a file transfer tool at a vendor

Breach notifications confirm thousands of users were affected after a vendor’s file transfer tool was compromised. No banking credentials were exposed.

Why it matters: Managed file transfer tools continue to be targeted and can expose concentrated data sets in one hit.

Bridgestone Americas: cyber incident disrupts North American plants

Bridgestone reported manufacturing disruption while investigations continue. No customer-data compromise has been confirmed at the time of writing.

Why it matters: Operational technology and plant networks remain high-value targets. Rapid containment is essential to limit downtime and supply chain impact.

Policy and oversight: historical misconfiguration disclosed

A previously undisclosed 2023 misconfiguration at a US federal intelligence sharing hub reportedly exposed restricted data to a large number of unauthorised users. The configuration was corrected, but the disclosure this week illustrates long-tail risk from configuration drift.

Why it matters: Configuration management and continuous assurance are as important as patching. Small oversights can scale into significant exposure.

What we are seeing this fortnight

  • Third party and SaaS risk dominates. Supplier breaches, CRM integrations and file transfer tools continue to ripple downstream.
  • Operational disruption is costly. JLR and Bridgestone show how quickly IT incidents can halt production.
  • Credential hygiene still matters. Plex highlights the ongoing risk from password reuse and weak multifactor adoption.

What to do this week

  • Audit suppliers and scopes. Review third party access, OAuth integrations and file transfer tools. Rotate tokens and keys where feasible and limit scopes to the minimum required.
  • Harden identity. Enforce phishing resistant MFA, monitor for impossible travel and disable legacy protocols such as basic auth and POP/IMAP where not required.
  • Backups and tabletop. Validate restore times and run an executive-level ransomware exercise that includes supplier outage scenarios.
  • Communications readiness. Pre-draft customer and regulator communications so you can respond within hours, not days.

For the best cyber security protection, contact us today. We will help you reduce third party risk, harden identities, and build real incident resilience so your organisation stays out of the headlines.

USEFUL LINKS
SERVICES
CONTACT US