TheCyberExpress

TCE Weekly Roundup: Denmark Leak, And $10M Bounty


This weekly roundup covers a massive exposure of personal data from Denmark’s national population register, a U.S. bounty on a Chinese hacker accused of stealing COVID-19 research, Japan’s plan to actively search for attackers hiding in its critical infrastructure, a pair of breaches at Japanese publisher Nikkei, a call for AI-driven decision-making in security operations, and a Massachusetts town’s ongoing recovery from an August cyberattack. 

Two threads run through this week’s stories. First, attackers keep getting in through doors that were already open: a company’s lawful access to a government register, employees’ hijacked email accounts, and unpatched mail servers. Second, the time between intrusion and discovery remains dangerously long, which is why governments and security leaders are pushing to find intruders sooner and respond faster. 

The Cyber Express Weekly Roundup 

Hackers Abuse Company’s Legitimate Access to Expose Data of 8.8 Million in Denmark 

The Danish government said unauthorized individuals obtained the names, addresses, and CPR numbers of roughly 8.8 million people from the Central Person Register. They did it by misusing the legal access granted to a private Danish company. The register holds records on about 11 million people, including residents, Danes living abroad, and deceased individuals. Read more… 

US Offers $10 Million Reward for Chinese Hacker Accused of Stealing COVID-19 Research 

The U.S. State Department is offering up to $10 million for information on Zhang Yu, a Chinese national accused of hacking COVID-19 research at U.S. universities on behalf of China’s Ministry of State Security. Zhang and his alleged partner, Xu Zewei, are also tied to the 2021 HAFNIUM campaign, which exploited Microsoft Exchange vulnerabilities to compromise more than 12,700 U.S. entities. Xu was arrested in Italy in 2025 and extradited to the U.S. in April 2026. Zhang remains at large. Read more… 

Japan to Launch Threat Hunting Program to Find Hidden Attackers in Critical Infrastructure 

Japan plans to partner with private companies in fiscal 2027 to proactively look for attackers who may already be sitting undetected inside power, telecom, and other critical infrastructure networks. The National Cybersecurity Office will build detection methods by recreating attack scenarios in a virtual environment and will share them with operators. The Defense Ministry will provide experienced personnel to companies on request. Read more… 

Nikkei Hit by Two Breaches as Hijacked Accounts Send 9,000 Malicious Emails 

Japanese publisher Nikkei disclosed on October 4 that attackers had taken over employees’ Microsoft 365 accounts. On September 30, they used those accounts to send roughly 9,000 emails with malicious links to staff and external contacts. Nikkei also revealed a separate breach of its Google Workspace accounts, ongoing since late July, that may have exposed the names and email addresses of 1,646 employees and business partners. Read more… 

Agentic AI Turns Cybersecurity Into a Race of Decision Speed 

In an opinion piece, Cyble’s Salleh Kodri argues that security teams no longer struggle to see threats. Their problem is “decision latency”: the time it takes to turn alerts from many tools into the right action. As AI accelerates attackers’ reconnaissance and decision-making, Kodri says defenders should use AI to correlate intelligence and act faster. Read more… 

Andover Confirms Attackers Accessed Town Systems in August Cyberattack 

Officials in Andover, Massachusetts, confirmed that the August 13 cyberattack involved unauthorized access to some town systems. They have not yet determined whether any data was stolen or whether personal information was involved. The town says it paid no ransom. It has hired a law firm and cybersecurity firm Vector3 to investigate, with costs covered by cyber insurance. Read more… 

Weekly Cybersecurity Takeaway 

Several of this week’s incidents started with access that looked legitimate. In Denmark, attackers abused a private company’s authorized connection to the national register instead of breaking in. At Nikkei, hijacked employee accounts sent thousands of malicious emails under a trusted name. 

Time is the other common thread. Nikkei’s Google Workspace breach ran for over two months before disclosure, and Andover still doesn’t know what was taken. Japan’s threat hunting plan assumes attackers may already be inside, and Kodri warns that spotting an alert means little if acting on it takes too long. 

Organizations should monitor third-party access as closely as their own staff’s. They should secure email accounts with phishing-resistant authentication and actively hunt for intruders rather than wait for alerts. 



Source link