September 2026 cybersecurity News Roundup

Yulia Kondrashova

Content and Community Manager at Axidian

September’s cybersecurity stories highlight persistent fraud and the need to secure expanding digital services. A business email compromise scheme cost a US company approximately $350,000, while fraud made up over 85% of incidents reported to Malaysia’s Cyber999 centre in Q2 2026.

Meanwhile, experts in Saudi Arabia and India called for stronger AI governance, and Burkina Faso assessed 205 government platforms for vulnerabilities. The shared priority: clear permissions, accountability, and practical security controls.

TL;DR

  • Impersonation remains a costly threat. A cross-border business email compromise case in Indonesia and Malaysia’s latest incident figures show how heavily cybercrime still relies on deceiving people.
  • AI needs clear access rules and accountability. Recent commentary from Saudi Arabia and India asks who owns AI agents, what they can access, and how their actions can be controlled.
  • Critical infrastructure protection is becoming more concrete. Senegal’s parliamentary action and Burkina Faso’s security assessments show different approaches to strengthening national digital services.
  • Response increasingly involves following the money. Indonesian authorities are connecting technical incident response with financial intelligence, while regional police cooperation remains a priority in MENA.
  • Security figures need context. Reported incidents, automated alerts, alleged leaks, and confirmed breaches describe different things. Keeping those distinctions clear matters when assessing risk.

Impersonation, payment fraud, and reported data exposure

The stories below show how familiar business communications and digital services can become routes into fraud. They also illustrate why reports about attacks need to distinguish verified findings from allegations.

Indonesia uncovers a business email compromise scheme targeting a US company

Indonesia’s financial-intelligence unit, PPATK, reported that a transnational fraud network used an email address closely resembling that of a business partner to manipulate a computer-hardware transaction. The victim transferred approximately $350,000 to an account prepared by the criminals. The case illustrates how a seemingly routine supplier conversation can lead to a substantial financial loss.

Indian experts highlight ₹22,495 crore in cyber-fraud losses during 2025

At an August government media workshop, cybersecurity experts cited ₹22,495 crore in losses and 2.815 million complaints recorded in India during 2025. Fake investment and trading schemes accounted for 76% of the reported financial losses, according to the presentation. The workshop emphasised prompt reporting and verification of suspicious communications to improve the chances of stopping fraud and recovering funds.

Malaysia reports a 24% quarterly increase in cybersecurity incidents

CyberSecurity Malaysia’s Q2 2026 report recorded 2,715 incidents handled by its Cyber999 centre, up from 2,188 in Q1. Fraud accounted for more than 85% of reports, while reported data breaches rose from 124 to 175. These figures describe incidents reported to and handled by the centre, rather than the total number of attacks across the country.

Morocco denies a breach following claims about security personnel data

A hacking group published names allegedly belonging to around 70,000 members of Morocco’s security and intelligence services. Moroccan authorities categorically denied that their information systems or security databases had been compromised. The report should therefore be read as an allegation accompanied by an official denial, rather than confirmation of a breach affecting 70,000 personnel.

AI adoption brings access and accountability into focus

The AI discussion is expanding beyond whether a model produces a reliable answer. As organisations allow AI systems to use applications and carry out tasks, security leaders are asking how to identify those systems, limit their permissions, and retain control over their actions.

Saudi Arabia’s AI expansion puts pressure on security frameworks

Security Middle East examines concerns that AI adoption in Saudi Arabia is moving faster than security and governance programmes. As businesses bring AI into core operations, the article highlights risks involving sensitive data, access permissions, model integrity, and external platforms. Its central argument is that security needs to be part of AI planning from the outset.

Reliance Industries CISO calls for identities and accountability for AI agents

Speaking at the ETCISO Annual Conclave, Reliance Industries CISO Dr. Durga Prasad Dube argued that autonomous agents need defined identities, roles, permissions, and responsible owners. Organisations should also be able to monitor agent behaviour, stop unsafe actions, and recover from failures. His message connects AI governance with familiar identity-security questions: what is acting, what is it allowed to do, and who is accountable?

Expert analysis examines how AI changes vulnerability discovery

An ETCISO contribution explores how autonomous AI can accelerate the discovery of software flaws and expose weaknesses across shared dependencies. The article argues that Indian enterprises need to prioritise remediation using actual exposure and business risk. As the volume of findings grows, identifying the vulnerabilities that matter most becomes as important as finding them.

Critical infrastructure and digital identity move up the agenda

National digital programmes depend on services remaining available and personal information staying protected. Recent developments show governments and industry leaders addressing that challenge through legislation, security assessments, and identity governance.

Senegal’s parliament adopts a critical-information-infrastructure security bill

An August report from OSIRIS describes the National Assembly’s adoption of a bill covering critical information infrastructure and digital security. The text addresses national protection arrangements and allows authorities to require cyber insurance for certain highly exposed organisations. It marks a further step in Senegal’s efforts to strengthen oversight as its digital economy expands.

Burkina Faso tests 205 public digital platforms

Burkina Faso assessed 205 government platforms for vulnerabilities, mapped 1,460 internet-accessible “.bf” platforms, and placed 28 public bodies under enhanced protection, according to We Are Tech Africa. The programme shows the practical work behind public-sector resilience: identifying exposed systems, assessing weaknesses, and strengthening protection around essential services.

Senegal ID Day puts digital identity governance in the spotlight

The first Senegal ID Day brought together public- and private-sector participants to discuss how existing identity systems could work together. Topics included civil-registration quality, biometrics, interoperability, and personal-data protection. The discussion highlighted that connecting services also requires clear decisions about how identity information is governed and protected.

GISEC Global brings regional cyber resilience into focus

GISEC Global 2026 brought cybersecurity authorities, regulators, infrastructure specialists, and business leaders to Dubai in September. Official coverage highlighted AI-enabled threats, pressure on critical infrastructure, and the need for international cooperation. The event’s emphasis on coordinated action reflects how closely national resilience now depends on relationships across sectors and borders.

Incident response connects technical evidence, money flows, and regional cooperation

Containing an affected system is only one part of responding to cybercrime. The next questions are where stolen funds have gone, which organisations hold relevant evidence, and how quickly that information can be shared.

Indonesia’s Anti-Scam Centre blocks Rp724 billion linked to fraud

In an update published on 1 September, Indonesia’s financial regulator reported that the Anti-Scam Centre had blocked approximately Rp724.1 billion linked to financial scams and returned Rp204.3 billion to victims. The figures cover the centre’s work from its launch in November 2024 through July 2026. They demonstrate the role of coordinated financial intervention alongside conventional cybersecurity measures.

PPATK calls for cyber incident response to follow the money

At IndoSec 2026, PPATK argued that incident handling should connect technical containment with the tracing and disruption of criminal financial flows. The agency called for timely reporting and closer intelligence sharing among financial institutions, digital-service providers, regulators, and law enforcement. The aim is to help investigators act before stolen money moves beyond reach.

MENA police leaders strengthen coordination against cyber-enabled crime

At an INTERPOL meeting in Cairo, regional police chiefs discussed ransomware, crime-as-a-service, and threats to digital infrastructure. They also reviewed the previously announced results of Operation Ramz, which involved 13 countries and led to 201 arrests. The September meeting focused on using cooperation and intelligence sharing to support further action against cross-border criminal networks.

Gabon clarifies why 900,000 alerts do not mean 900,000 breaches

Gabon’s digital infrastructure agency, ANINF, clarified that the 900,000 alerts recorded by monitoring systems should not be interpreted as successful intrusions. The agency stressed the importance of analysing what alerts represent and how teams respond to them. The distinction is useful well beyond government: security reporting needs to explain impact and response, rather than rely on a large headline number.

Turning the news into practical security priorities

Taken together, these stories point to a common challenge: organisations need a clearer view of who and what can act inside their systems, alongside the ability to respond quickly when that trust is abused.

For security leaders, useful questions include whether sensitive access has an accountable owner, whether unusual activity can be investigated with enough context, and whether response plans involve the business partners needed to contain the damage. AI agents, suppliers, employees, and public digital services bring different risks, but each requires clear permissions and oversight.

For further reading, explore the Axidian blog and its practical guide to privileged access management.

About the Author

Yulia Kondrashova

Content and Community Manager at Axidian

Over three years of experience in cybersecurity and content creation, with expertise in identity security. Focused on developing educational content that makes complex security topics clear, relevant, and practical for professionals.