AI and IT News Recap: October 6, 2026: Denmark's ID Register Is Drained Through One Company's Login, a Buried Cable Darkens the City of London, and Reflection AI Unveils Beam
By Noah Smith, Owner & Consultant, KeyChange Technologies ยท October 6, 2026

A lighter news day, but the top story is a big one: a single company's legitimate login was enough to walk off with the identity details of 8.8 million people.
๐ The AI and IT news at a glance
Here is today's AI and IT news, the short version:
- Denmark's national ID register gets drained through one company's trusted access: 8.8 million people exposed.
- A single failed underground cable blacks out a slice of the City of London, card payments included.
- Reflection AI unveils Beam, a big American open-weight model pitched against DeepSeek.
- OpenAI is bringing visual ads into ChatGPT's image generator.
- OpenAI starts quietly watermarking ChatGPT and Codex text in the EU, and lets any developer opt in.
Yesterday's recap is here if you missed it: AI and IT News Recap: October 5, 2026.
๐ Top story: Denmark's citizen register was drained through one company's legitimate access
Denmark's government said on Monday that attackers pulled names, addresses, and CPR numbers (the Danish equivalent of a Social Security number) for about 8.8 million people from the Central Person Register, the database that underpins almost every interaction a Dane has with the state, their bank, and their doctor. That number is bigger than the country's population because the register also holds emigrants, deceased people, and other records going back decades. Early reports put the figure at 8 million; the government's own count is 8.8 million, roughly 80 percent of the register's 11 million records.
The striking part is how it happened. Nobody broke through a firewall. The attackers abused a private Danish company's lawful, contracted access to the register and ran automated lookups for about 10 days in September before an employee noticed unusual activity on October 2. Digitalization Minister Christina Egelund said the safeguards around that kind of access "had not been solid enough," and acknowledged alarms should have gone off given how long it ran. Police are investigating, the data protection authority has been notified, and the government is even weighing whether to issue replacement CPR numbers. Danish experts are already warning that the stolen data will make phishing messages that impersonate authorities far more convincing.
In short: Attackers used one company's legitimate access to Denmark's national ID register to pull personal data on 8.8 million people over roughly 10 days, and nobody noticed until October 2.
What it means for your business: Your biggest exposure may not be your own login page but the partners, integrators, and vendors you have given standing access to your data. If that access is not monitored for unusual volume, a "trusted" connection can quietly empty your systems.
My take: This is the breach pattern that keeps me up at night, because it does not look like an attack. It looks like a customer doing their job, just a lot more of it. Make a list of every outside company and app with access to your customer, HR, or financial data, ask whether each one still needs it, and turn on alerts for unusually large exports or lookups. A ten-day head start is what you get when nobody is watching the volume.
Source: The Hacker News: Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
๐ก๏ธ IT and security
โก One failed cable darkens part of the City of London, and card payments with it
Around midday Monday, a fault on an underground electricity cable knocked out power across about 33 postcodes in central and east London, stretching from Hackney and Shoreditch into the City between Aldgate East and Liverpool Street. Office buildings in the Square Mile went dark, departure boards at Liverpool Street station went blank, and shops in the station could not take card payments. Essex Road station was closed after its platform lighting failed, and some traffic signals and CCTV cameras in Hackney were affected.
UK Power Networks confirmed the cause was "a fault on an underground electricity cable in the local area," and power came back after a couple of hours. City AM described it as one of the largest unplanned outages in central London in several years. Nobody hacked anything. One piece of buried infrastructure failed, and a district full of banks, law firms, and retailers stopped working.
In short: A single underground cable failure cut power to thousands of homes and businesses across 33 London postcodes for a couple of hours on Monday, including card payments at Liverpool Street station.
What it means for your business: If your till, your Wi-Fi, and your phones all depend on the same building's power, a single outside failure takes down your ability to sell. A two-hour outage at lunchtime is real money.
My take: This is the cheapest lesson of the week. Ask yourself what happens if the power goes out at noon tomorrow: can you still take a payment, answer the phone, and reach your files? A small battery backup on the router and card reader, a card reader that can fall back to cellular, and cloud-hosted files cover most of it for very little money. Your redundancy is only redundant if it does not share the same plug.
Source: City AM: Power cut leaves City offices in the dark
๐ค AI
๐ Reflection AI unveils Beam, a large American open-weight model
Reflection AI, the Nvidia-backed startup founded by former Google DeepMind researchers and last valued at $25 billion, introduced Beam on Monday: a 501-billion-parameter open-weight model (23 billion parameters active at a time) with a 1-million-token context window. The company says the weights and technical documentation will be released this month through major cloud and AI hosting platforms.
Reflection claims Beam matches Z.ai's GLM-5.2 on reasoning benchmarks while needing three to four times less computing power to run, and positions it squarely as a Western alternative to Chinese open models from DeepSeek and Qwen, which many businesses have been reluctant to adopt. The pitch is aimed at enterprises and governments that want to run and customize a capable model on their own infrastructure. Those benchmark claims are the company's own and have not been independently tested yet.
In short: Reflection AI announced Beam, a 501-billion-parameter open-weight model it says rivals top Chinese open models at a fraction of the compute, with weights due out in October.
What it means for your business: More capable open models mean more options to run AI privately on your own or your provider's infrastructure instead of sending data to a big AI vendor, which matters if you handle sensitive client data.
My take: Most small businesses will never host a 501-billion-parameter model themselves, and that is fine. What matters is the trend: the open alternatives keep getting closer to the paid ones, which pushes prices down and gives your software vendors more choices. Wait for independent testing before believing the benchmark slide.
๐ผ๏ธ OpenAI is bringing visual ads to ChatGPT's image generator
OpenAI announced on Monday that it will start testing a new visual ad format that appears while ChatGPT is generating images, beginning later this month in the U.S. with a select group of advertisers. The ads are labeled and kept separate from the images users create. OpenAI also added measurement integrations (Hightouch, Tealium, LiveRamp, AppsFlyer, Triple Whale, and others) so advertisers can track conversions, plus brand-safety pilots with DoubleVerify and Integral Ad Science that OpenAI says assess placements without access to private conversations.
OpenAI says ChatGPT now reaches 1.2 billion people a week and shared early advertiser results, including WeightWatchers reporting a 15.3 percent lower cost per acquisition on ChatGPT than its paid search benchmark. Businesses can register interest at ads.openai.com.
In short: OpenAI will begin testing labeled visual ads inside ChatGPT's image generation later in October in the U.S., alongside new ad measurement and brand-safety tools.
What it means for your business: ChatGPT is turning into a real advertising channel, with tracking tools that plug into the same systems marketers already use for Google and Meta.
My take: If you already buy search or social ads, put ChatGPT on your watch list rather than your budget. The early case studies are the ones OpenAI chose to publish, so wait for the format to open up and for independent numbers. On the flip side, if your team uses free ChatGPT accounts for work, expect a more commercial experience and a good reason to standardize on a business plan.
Source: OpenAI: Building advertising for the way people use AI
๐งฐ Tools for builders and business AI
๐ง OpenAI starts watermarking ChatGPT and Codex text in the EU, and developers can opt in now
OpenAI is rolling out invisible watermarking, called textGrain, that subtly shifts word choices in generated text to leave a statistical pattern a detector can spot without changing how the text reads. Starting Monday, API developers worldwide can opt in (it is off by default), and in the coming weeks OpenAI will automatically watermark eligible ChatGPT and Codex output for users in the EU. Access to the detector is limited for now to approved researchers and expert organizations.
OpenAI is upfront about the limits. In its own testing, swapping 10 percent of words for synonyms cut detection from about 92 percent to 66 percent, and swapping 25 percent dropped it to 17 percent. It also works poorly on subjects like math where there are few word choices. The company's own warning: "The absence of a detected watermark does not prove human authorship."
In short: OpenAI launched opt-in text watermarking for API developers worldwide and will apply it automatically to ChatGPT and Codex output in the EU in the coming weeks.
What it means for your business: If you have EU staff or customers, AI-written text from ChatGPT may soon carry a hidden marker; if you build on OpenAI's API, you now have a switch to mark your own AI output.
My take: Treat this as a disclosure tool, not a lie detector. A light edit defeats it, so do not use "no watermark found" to accuse a writer, a student, or a vendor of anything. If you publish AI-assisted content, the simpler and more durable policy is to say so.
Source: BleepingComputer: OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU
That is today's AI and IT news. If one thing from today makes your to-do list, make it the vendor access review: find out who outside your company can pull data out of your systems, and whether anyone would notice if they pulled a lot of it.