> ## Content Index
> Fetch the complete content index at: https://unlocked.everykey.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# October Recap - The Breach Report
- URL: https://unlocked.everykey.com/october-recap-the-breach-report/
- Published: 2025-11-20T22:10:03.000Z
- Updated: 2026-06-24T16:17:47.000Z
- Description: Qantas, DoorDash, Toys R Us, GlassWorm supply chain, and more — the top 7 data breaches of October 2025 and key lessons for security teams.
- Author: Nick Marsteller
- Tags: The Breach Report, #beehiiv, #Import 2026-04-29 08:19

Hello and welcome back to **The Breach Report!**

October kept the pressure on. From airlines to delivery platforms, universities to retail chains — attackers again homed in on weak vendor links, credential misuse, and third-party system exposure.

The recurring themes? **Social-engineered vendor access, SaaS/data-platform misuse, and unsecured backend systems.**

Follow along and subscribe to stay ahead of the latest cyber threat and data breach developments.

---

## 🚨 Top 7 Data Breaches of October 2025

### 1\. Qantas Airways / Third-Party Contact Centre (Canada/Australia/Global)

- **What happened:** A third-party customer-service platform used by Qantas suffered a compromise; data of roughly 5 million customers was leaked.
- **Impact:** Names, email addresses, frequent flyer numbers, phone numbers and dates of birth exposed. No payment or passport data disclosed.
- **Lesson:** Even well-known airline brands can be derailed via vendor platforms — your customer-service or contact-centre provider is a high-risk vector.
- **Source:** [**Read More**](https://www.theguardian.com/business/2025/oct/11/hackers-leak-qantas-data-containing-5-million-customer-records-after-ransom-deadline-passes?utm%5Fsource=unlocked.everykey.com&utm%5Fmedium=referral&utm%5Fcampaign=october-recap-the-breach-report)

### 2\. DoorDash (USA / Canada)

- **What happened:** On October 25, DoorDash discovered a social-engineering attack on an employee that resulted in exposure of user, merchant and “Dasher” contact information.
- **Impact:** Names, addresses, email addresses and phone numbers were accessed. No SSNs, payment card numbers or government IDs confirmed.
- **Lesson:** Social engineering remains a potent tactic — even when core systems haven’t been breached, perimeter access via staff remains a critical weakness.
- **Source:** [**Read More**](https://www.securityweek.com/doordash-says-personal-information-stolen-in-data-breach/?utm%5Fsource=unlocked.everykey.com&utm%5Fmedium=referral&utm%5Fcampaign=october-recap-the-breach-report)

### 3\. Toys "R" Us Canada Retail Data Exposure (Canada)

- **What happened:** Attackers published customer records from the retailer’s backend database. The incident dates to late July but was confirmed in October.
- **Impact:** Names, email addresses, physical addresses and phone numbers leaked. No payment card or password data reported.
- **Lesson:** Retail chains with large customer bases remain lucrative targets — even seemingly “low-risk” PII without payment data can fuel phishing and identity fraud.
- **Source:** [**Read More**](https://www.bitdefender.com/en-us/blog/hotforsecurity/toys-r-us-canada-confirms-customer-data-breach-after-dark-web-leak?utm%5Fsource=unlocked.everykey.com&utm%5Fmedium=referral&utm%5Fcampaign=october-recap-the-breach-report)

### 4\. Municipal / Local Government Cyber Disruptions (USA)

- **What happened:** Multiple U.S. counties (e.g., in Texas, Tennessee, Indiana) suffered cyber incidents in October that disabled service portals, login systems and network access.
- **Impact:** While confirmed data theft is minimal, critical citizen services were disrupted (payments, courts, tax portals).
- **Lesson:** The public-sector threat is increasingly about availability and disruption, not only exfiltration — consider service resilience as part of your breach preparedness.
- **Source:** [**Read More**](https://strobes.co/blog/top-data-breaches-of-october-2025/?utm%5Fsource=chatgpt.com#:~:text=can%20do%20differently.-,1.%20Cyber%20incidents%20in%20Texas%2C%20Tennessee%2C%20and%20Indiana%20disrupted%20key%20local%20government%20services,-Incident%20Overview)

### 5\. Western Sydney University (Australia/Global)

- **What happened:** A breach in the student-management system (cloud-hosted) via third-party upstream provider resulted in extensive data theft.
- **Impact:** Names, dates of birth, passport and visa details, disability/health records, bank account numbers — extremely sensitive data extracted.
- **Lesson:** Universities (and by extension academic institutions in North America) remain high-risk — complex vendor chains increase attack surface.
- **Source:** [**Read More**](https://www.cyberdaily.au/security/12816-western-sydney-university-confirms-personal-data-stolen-in-latest-cyber-attack?utm%5Fsource=unlocked.everykey.com&utm%5Fmedium=referral&utm%5Fcampaign=october-recap-the-breach-report)

### 6\. Developer Supply-Chain Attack – “GlassWorm” in VS Code Extensions

- **What happened:** Malicious extensions for Visual Studio Code were deployed and downloaded 35,000+ times, enabling credential theft and remote-access propagation.
- **Impact:** Developer toolchains compromised, source credentials and CI/CD access risked — broad implications for organizations relying on open-source ecosystems.
- **Lesson:** Your “internal” dev tools may be an external risk vector — supply-chain attacks transcend SaaS access and include developer workflows.
- **Source:** [**Read More**](https://fluidattacks.com/blog/glassworm-vs-code-extensions-supply-chain-attack?utm%5Fsource=unlocked.everykey.com&utm%5Fmedium=referral&utm%5Fcampaign=october-recap-the-breach-report)

### 7\. Credential / Infostealer Leak – 183 Million Email Accounts (Global, including U.S.)

- **What happened:** A large cache of email accounts (including Gmail users) and passwords identified via an infostealer malware campaign that operated quietly for months.
- **Impact:** Credentials harvested enable phishing, account take-over, lateral movement; the underpinning threat to enterprise identity posture is significant.
- **Lesson:** Credential hygiene, MFA enforcement and monitoring of exposed logins remain foundational. A breach of identity is a breach of access.
- **Source:** [**Read More**](https://nypost.com/2025/10/27/business/183m-email-passwords-exposed-in-data-leak-including-millions-of-gmail-accounts-heres-how-to-check-if-yours-is-safe/?utm%5Fsource=unlocked.everykey.com&utm%5Fmedium=referral&utm%5Fcampaign=october-recap-the-breach-report)

---

## 🖥️ Industry Highlights: What’s in the Hot Seat

- **Vendor / third-party intrusion** remains one of the most leveraged vectors (Qantas, Toys “R” Us, municipal governments).
- **Credential & social-engineering attacks** continue to drive breaches even when technical perimeter defences are intact (DoorDash, email infostealer).
- **Developer & toolchain supply-chain attacks** are ascending — GlassWorm is a cautionary tale for DevSecOps.
- **Availability/disruption in public sector** is as serious as data theft — local governments impacted functionality, not only data.

---

## 🛡️ Pro Tips & Tools

- Enforce vendor access review — treat every third-party link as a potential attacker path.
- Mandate MFA + passkey implementations + identity-threat monitoring — credentials are still a primary target.
- Segment development environments and restrict extension installs; apply inventory and version controls to dev-tool chains.
- Build service-resilience playbooks for non-data breaches — offline payment alternatives, immutable backups, alternate login channels.
- Monitor dark-web and infostealer feeds for credential exposures linked to your domains — early detection can head off lateral infiltration.

---

## ⚠️ Emerging Threats to Watch

- **Toolchain compromise** — both developer and operational tools are being weaponised.
- **Credential-leak commoditisation** — large volumes of exposed logins feed phishing and account-takeover campaigns.
- **Vendor ecosystem cascade failures** — one compromised supplier can ripple through multiple industries.
- **Public-sector disruption incidents** — not just data theft, but service denial is on the rise.

---

## 💡 Final Thoughts

October reinforced a truth: **It’s not only what you protect internally, but who you grant access, and how you manage identity and toolchain trust.**

From major airlines to delivery apps, retail chains to dev-environments, the path of least resistance is rarely the firewall — it’s the person, the token, or the vendor system. Defending your perimeter is no longer sufficient — you must lock down every integration, every identity channel, and every critical service link.

**Stay vigilant, stay proactive, and we’ll bring you the November report next month.**