
Our monthly briefing on the attacks, the regulatory moves and the wider security news that matter to regulated organisations in India. Current issue: September 2026.
Compiled from public reporting and official sources. Items marked alleged or reported were, at the time of writing, not officially confirmed by the named organisation or regulator. This briefing is for awareness, verify against primary sources before acting on any item.
Notable incidents disclosed or reported in September 2026, spanning healthcare, government, transport and SaaS.
McKesson disclosed an incident through an SEC Form 8-K in late August after discovering it on 25 August. The ShinyHunters group claimed roughly 284 million patient-related records and demanded about $55 million, but told reporters the figure is a raw count of database rows, not unique individuals, and that it had not finished analysing the data. McKesson has not confirmed the scale.
Why it matters: Claimed figures are routinely inflated and unverified. The SEC 8-K cadence and extortion theatre now shape the first 72 hours of a healthcare incident as much as the forensics do.
Source: BleepingComputer
The US Defense Manpower Data Center confirmed attackers accessed a file-sharing server for roughly nine months, exposing sensitive personal data on more than three million people. Notification letters were dated 18 September, and those affected were offered credit monitoring.
Why it matters: Nine months of undetected access to a file-sharing server is a logging and monitoring failure, exactly the controls CERT-In’s log-retention and reporting rules exist to force.
Source: Cybersecurity News
Healthcare-technology firm Veradigm (formerly Allscripts) disclosed in an SEC Form 8-K that an attacker obtained credentials from a third-party vendor’s environment for a Veradigm customer-services API, then used that access to copy patient data, including some Social Security numbers. A group calling itself The Gentlemen claimed about 3.5 million records.
Why it matters: Your vendor’s breach becomes your breach. API access tied to vendor credentials needs the same rotation, scoping and monitoring as your own.
Source: HIPAA Journal
The screenshot service Gyazo (operated by Helpfeel) confirmed an attacker exploited a flaw in its image-upload server on 11 September, running arbitrary commands and exposing about 23.62 million user records including password hashes, authentication tokens and session IDs, plus metadata on hundreds of millions of images. The route was fixed by 12 September and payment data was not affected.
Why it matters: Exposed authentication tokens enable account takeover long after passwords are reset. Token invalidation belongs in every breach playbook.
Source: BleepingComputer
Keio Corporation confirmed a ransomware attack on a group server on 26 September that disrupted business systems, mainly its hospitality division, while train operations continued. In a separate incident the same weekend, Tokyo Metro disclosed unauthorised access to roughly 59,000 members’ email addresses.
Why it matters: Transport and hospitality operators straddle IT and operational technology; ransomware that forces a network shutdown is a resilience and continuity test, not only a data-privacy one.
Source: BleepingComputer
What is live on the India compliance calendar this month across RBI, SEBI, IRDAI, DPDP and CERT-In.
With the DPDP Rules phased in, the 12-month provisions, including the Consent Manager framework and Board registration, commence on 13 November 2026, ahead of the full compliance deadline of 13 May 2027. Data Fiduciaries should be standardising consent records and designing for interoperability now.
Why it matters: The Consent Manager interface is not a last-minute integration. Firms that standardise consent capture and withdrawal early avoid a rebuild later.
Source: MeitY
The IRDAI Information and Cyber Security Guidelines, 2026 (issued 6 April 2026) require compliance from the financial year that opened on 1 April 2026. Insurers and intermediaries are working through governance, assurance and audit obligations in their first cycle under the reissued guidelines.
Why it matters: First-year compliance is where gaps surface; board-level governance and independent assurance are the pieces most often left late.
Source: IRDAI
After the 31 July 2026 reset, the RBI framework is a set of entity-class Directions, one per class. The testing cadence is vulnerability assessment at least every six months and penetration testing at least annually for critical and DMZ-facing systems, cloud included; a tested system later breached through a missed vulnerability counts as a deficiency against the auditor.
Why it matters: The scope test is disjunctive and the VA cadence is twice a year, not annual. Mapping to the correct Direction is the first step for every regulated entity.
Source: Reserve Bank of India
With critical Citrix NetScaler flaws under active exploitation (see below), any confirmed compromise of an India-based system brings CERT-In’s six-hour incident-reporting obligation into play, alongside sector rules from RBI, SEBI or IRDAI.
Why it matters: A single intrusion can start several reporting clocks at once. A unified incident-response plan with regulator-specific annexes keeps you inside the tightest window.
Source: CERT-In
Vulnerabilities, credential threats and AI-security developments worth a leadership read.
Citrix confirmed on 27 September that two critical NetScaler ADC and Gateway flaws, CVE-2026-88771 and CVE-2026-88772 (both CVSS 9.5), were being exploited in the wild, with CVE-2026-88771 allowing unauthenticated remote code execution on default configurations. CISA added both to its Known Exploited Vulnerabilities catalog with a 30 September deadline, and Citrix warned that patching alone does not remove the risk of prior compromise.
Why it matters: Internet-facing edge appliances remain the softest target. Patch immediately and hunt for signs of compromise, because a fix does not undo access already taken.
Source: SecurityWeek
Analysis of recent stealer-log data found infostealers harvesting corporate AI accounts, sessions and API keys, handing attackers access to sensitive data, compute and connected systems.
Why it matters: AI accounts and API keys are now crown-jewel credentials. Treat them like production secrets, with rotation, scoping and monitoring.
Source: Security Affairs
A breach at market-research provider Klue exposed keys to its customers’ cloud services, letting attackers reach and extort close to 200 companies, several of them well-known security vendors.
Why it matters: One compromised SaaS provider can hand attackers the keys to hundreds of customers. Vendor cloud-key handling is a first-order supply-chain risk.
Source: TechCrunch
Investigators documented an AI agent’s path from an ordinary research task into reconnaissance activity, part of a wider trend of AI agents being turned toward offensive use.
Why it matters: Autonomous agents lower the cost of reconnaissance at scale. Monitoring and guardrails for AI tooling now belong in the threat model.
Source: Security Affairs
Whether it’s a breach-response gap, a looming DPDP deadline or an urgent patch-and-test cycle, our CERT-In empanelled team can help you act on what matters.