Here are some weekly APAC cybersecurity snippets that you might find interesting.
As an aviator, this news struck me. On September 10, Vietnam suffered a data breach when cybersecurity researchers found over 220 million flight records of passengers and crew available on a server located in Hanoi. The records were from an Advance Passenger Information System (APIS) located on Viettel IP space and contained nine years of data, with flight manifests, passport numbers, birth dates, and trip itineraries. The primary cause was an administrative oversight that left an alternate cloud path open with factory-default credentials. The event raises the risk for both travelers and airlines of targeted identity theft and sophisticated travel-related phishing scams. The fix is to make sure that organizations remove default passwords fully, automate the validation of zero-trust network access across all subnets, and inspect legacy database endpoints regularly instead of presuming secondary cloud instances have been isolated.
ANZ’s Mathspace revealed on September 8 that threat actors accessed an internal reporting database that leaked personal records of 1,079,819 students, parents, and teachers. Threat actors exploited a known SQL injection vulnerability in an on-premise Metabase instance that was not patched in a timely manner after upstream vendor advisories. No passwords or academic grades were exfiltrated, but exposed names, emails, and account metadata may pose spear-phishing risks for school communities. The problem notes that secondary analytics servers often have large internal privileges, even if they don’t have customer-facing interfaces. To defend holistically, organizations must automate patch orchestration for all self-hosted dependencies, enforce tight principle-of-least-privilege credential vaulting or zero-trust between analytics platforms and central data warehouses, and mandate post-patch compromise assessments.
On September 4, Hong Kong SAR’s police issued a warning after phony customer service phone fraud triggered a 56 percent rise in telecommunication swindles, causing damages to the community of more than HK$900 million. Systematically, fraudsters call persons posing as representatives of banks, telecom carriers, and e-commerce platforms, saying there is a problem with the account to lure victims into wiring savings or leaking verification codes. Police said 1 individual is a victim every hour in the city. The backlash from the community demonstrates how contemporary digital frauds blend weaponized social engineering with call spoofing to bypass typical digital caution. To counter this issue, telco-level AI speech-traffic filtering, cross-sector transactional verification protocols between banks and mobile operators, and widespread use of phishing-resistant authentication systems that cannot be compromised over voice contact are required.
Japan’s National Police Agency confirmed on September 10 that ransomware attacks soared to 123 cases in the first half of the year, with corporate disruption increasingly resulting in complete operational shutdowns. Threat actors are combining perimeter vulnerability scanning (an average of roughly 13,700 suspicious connection attempts daily) with double-extortion methods to disable over half of victim organizations for more than 30 days as they hone their extortion playbooks. To stop this systemic fallout, enterprises may abandon fragmented legacy perimeters and migrate to holistic zero-trust architectures that guarantee critical offline immutable backups, continuous endpoint surveillance, and centralized privilege controls that halt lateral network sprawl before threat actors can reach operational payloads.
On September 4, India’s Central Bureau of Investigation (CBI) conducted simultaneous raids at 89 sites in 20 states under Operation Chakra-VI to break down organized “digital arrest” syndicates involved in multi-crore extortion scams. Working through intimidation, the syndicates faked credentials and stacked video conversations mimicking law enforcement to compel victims into extended virtual isolation while siphoning monies through sophisticated networks of mule bank accounts. To defend against these socially designed psychological intrusions, people need stringent digital proficiency, real-time interception of banking irregularities, and strict cryptographic verification on communication channels to prevent fraudulent institutional impersonation at first contact.
###

Dr Seamus Phan is head of content at Microwire.news (aka microwire.info), a content outreach and amplification platform for news, events, brief product and service reviews, commentaries, and analyses in the relevant industries. Part of McGallen & Bolden Group initiative. Copyrights belong to the respective authors/owners and the service is not responsible for the content presented.
