AI and IT News Recap: October 7, 2026: Hackers Hijack ASOS's Own App Alerts, the FBI Blames a Contractor's Skipped Patch, and Claude Moves Into Google Docs
By Noah Smith, Owner & Consultant, KeyChange Technologies · October 7, 2026

Here is today's AI and IT news, cut down to what a busy owner actually needs: one retailer's own app turned into a ransom note, a federal breach traced to one skipped patch, two big breach notices, and Claude moving into Google Docs. Yesterday's recap is here if you missed it.
📌 The AI and IT news at a glance
- ASOS's own app pushed a "hacked" alert to shoppers after attackers got into a third-party messaging platform.
- The FBI says its ShinyHunters breach came down to one patch a contractor never applied.
- Georgia Power and Alabama Power warn about 400,000 customer accounts accessed through their online portal.
- Arizona's courts say one clicked email link exposed data on 1.3 million people.
- Fake ChatGPT and Gemini sites are stealing ad accounts and MFA codes with a convincing fake Google login.
- A critical Atlassian flaw is under attack in self-hosted Jira, Confluence and Bitbucket within hours of a public exploit.
- Wikimedia says rogue OpenAI agents tried to turn its tools into proxies.
- A musician gets 18 months for a $10 million AI streaming scam.
- Claude now works inside Google Docs, Sheets and Slides in public beta on paid plans.
- Anthropic is giving startups a free year of Claude Team plus $1,000 in API credits.
🔝 Top story: Hackers use ASOS's own app to tell customers it was hacked
On Tuesday, ASOS app users started getting a push notification titled "ASOS hacked." It came through the retailer's official app, not a spoofed text or email, and it was addressed to ASOS's data protection officer and IT team: the senders said they had "fully compromised the Snowflake instance" and threatened to leak data unless the company engaged with them. A group calling itself Xuanye Group claimed the attack on a newly created Telegram channel, and the notification linked out to that channel.
ASOS confirmed that a third-party platform it uses to send customer notifications was accessed without authorization, and that basic personal information including names and contact details may have been exposed. The company says payment card details and account passwords were not affected, the website and app kept working, and it has restricted access to the notification platforms while working with outside specialists and authorities. What ASOS has not confirmed is the attackers' central claim: it has not said whether its Snowflake data environment was actually breached, and it has not said how many customers are affected. Treat the "fully compromised" line as an unverified claim from the attackers for now.
In short: Attackers got into a messaging platform ASOS uses and pushed a ransom-style "ASOS hacked" alert to customers through the official app.
What it means for your business: The tools you use to talk to customers (push, SMS, email marketing platforms) are a direct line into their pockets, and whoever controls the login controls your voice. Know who has admin access to each of them and make sure it is protected with strong MFA.
My take: The data exposure here sounds limited so far, but the embarrassment is not. Your customers trust a message from your app more than anything else you send, which is exactly why attackers want the keys to it. Most small businesses have three or four of these "send to everyone" tools, and they are rarely on anyone's security list. Put them on yours.
Source: BleepingComputer: ASOS confirms data breach after "HACKED" in-app notifications
🛡️ IT and security
The FBI says its breach came down to one patch a contractor skipped
The FBI has publicly blamed a contractor for the September breach claimed by the ShinyHunters gang. The attackers got into the bureau's jobs website and personal information on thousands of FBI employees through an Oracle PeopleSoft HR platform managed by Accenture. According to SecurityWeek, FBI cyber chief Brett Leatherman said the incident happened because a contractor "failed to implement a security patch explicitly issued to secure the platform." The FBI removed the Accenture contractor involved.
Google had already warned that ShinyHunters was actively hunting vulnerable PeopleSoft systems, so this was not a surprise attack on an unknown flaw.
In short: The FBI says ShinyHunters got in because a contractor managing its PeopleSoft HR system never applied an available security patch.
What it means for your business: Handing a system to a vendor does not hand off the risk. If an outside firm manages your HR, payroll or accounting software, you need proof that it is being patched, not an assumption.
My take: If the FBI can get burned by a skipped update on an HR system, so can a 20-person company whose IT guy "handles that." Ask your managed provider one simple question this week: "Show me the last time each of our business systems was patched." A good vendor answers that in an hour.
Source: SecurityWeek: FBI Blames Contractor's Missed Patch for ShinyHunters Breach
Georgia Power and Alabama Power warn about 400,000 customer accounts
Southern Company, the parent of Georgia Power, Alabama Power and Mississippi Power, says an unauthorized party got into its online customer account portal. Roughly 300,000 Georgia Power accounts and about 100,000 Alabama Power accounts are affected, with Mississippi Power customers also involved in numbers the company has not broken out.
The exposed information includes names, mailing addresses, phone numbers, email addresses, the last four digits of Social Security numbers (or of business tax IDs for business accounts) and basic account details. The company says bank account numbers, payment card numbers and driver's license numbers were not accessed. It has not said how the attacker got in. Customers are being notified by mail and email and offered a year of free credit monitoring.
In short: Southern Company says about 400,000 Georgia Power and Alabama Power customer accounts were accessed through its online portal.
What it means for your business: If you are a customer of these utilities, including on a business account, expect very convincing fake "your power bill is overdue" calls and emails, because the scammers now have your name, address and account details.
My take: Partial Social Security and tax ID digits sound harmless until someone reads them back to you on the phone to "verify" they are from the power company. Tell whoever handles your bills that the utility will not demand instant payment by phone, and that any shutoff threat gets checked by calling the number on a real bill.
Source: SecurityWeek: Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts
One clicked link exposed 1.3 million people in Arizona's court system
The Arizona Supreme Court says personal information on about 1.3 million people with unpaid court fees and fines was stolen in a cyberattack that started when a court employee clicked a malicious link in an email. The records go back roughly 30 years and include names, case numbers and Social Security numbers tied to the state's FARE debt collection program. Nearly 30,000 active and inactive protective orders and about 150,000 confidential Foster Care Review Board reports dating to 2010 were also accessed.
The court says the intrusion was found on a backup server on September 24 and shut down within about two hours, that no records were altered or deleted, and that it has no evidence the data has been used or shared. The FBI is investigating.
In short: A phishing click let hackers steal court records on 1.3 million Arizonans, including Social Security numbers, protective orders and foster care reports.
What it means for your business: Two hours was fast, and it was still enough time to lose 30 years of records. Phishing remains the front door, and old data you are keeping "just in case" is what turns a short intrusion into a huge breach.
My take: The detection here was decent. The damage came from how much sensitive history was sitting on one reachable backup server. Every business has an equivalent: an old shared drive or export nobody has touched since 2019. Deleting what you do not need is the cheapest security project you will ever run.
Fake ChatGPT and Gemini sites are stealing ad accounts and MFA codes
Researchers at browser security firm Island have uncovered a phishing campaign, running since at least March, that uses fake versions of ChatGPT, Gemini, Claude and Perplexity to target people who manage advertising accounts: agency staff, media buyers and admins with control over client ad budgets. When a victim clicks "Connect," the site draws a fake Google sign-in window inside the page, complete with a realistic title bar and the web address you would expect to see.
Behind the scenes, human operators then ask for the password and whatever second factor the account uses, from SMS and authenticator codes to Okta push approvals, so the usual MFA protections get walked straight past. The attackers' Telegram control channel showed hundreds of victim submissions, though not all of those necessarily led to a takeover.
In short: Fake AI tool sites show a counterfeit Google login to steal ad managers' passwords and MFA codes in real time.
What it means for your business: Anyone on your team who runs Google or Meta ads, or who signs into new AI tools with a Google account, is a target. A stolen ad account can burn through a budget fast.
My take: One simple trick from the researchers: try dragging the login pop-up outside the browser window. A real one moves; a fake one cannot leave the page. The longer-term fix is passkeys or security keys on your ad and Google admin accounts, because those cannot be typed into a fake box.
Source: BleepingComputer: Fake ChatGPT, Gemini sites steal advertising accounts, MFA codes
A critical Atlassian flaw is under attack hours after a public exploit
Attackers are exploiting CVE-2026-21589, a critical vulnerability in self-hosted Atlassian products: Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo and Crowd Data Center, plus Crucible and Fisheye. It lets an attacker with no login read files on the server, and in Jira setups tied to Crowd, researchers showed they can pull plaintext credentials from configuration files and work up to admin access.
Honeypots picked up exploitation attempts from multiple IP addresses within hours of the technical proof of concept going public on October 7. Atlassian's cloud versions are not affected.
In short: A critical, no-login file-reading flaw in self-hosted Jira, Confluence and other Atlassian products is being actively exploited.
What it means for your business: If you or a vendor run Jira or Confluence on your own servers, patch today or restrict access until you can. If you use Atlassian Cloud, you are not affected.
My take: This is my one technical pick of the day because Jira and Confluence hold an enormous amount of business knowledge, and this one went from paper to live attacks in hours. If you are not sure whether your Atlassian tools are cloud or self-hosted, that is the first thing to find out.
Source: BleepingComputer: Hackers exploit critical Atlassian flaw after public PoC release
🤖 AI
Wikimedia says rogue OpenAI agents tried to turn its tools into proxies
The Wikimedia Foundation, which runs Wikipedia, has published its findings on activity by OpenAI agents across its sites. It says the agents generated millions of automated API requests, crawled millions of pages on Wikidata and Wikimedia Commons, and sent hundreds of thousands of queries to the Wikidata Query Service, traffic that contributed to a partial outage of that service in May.
More pointedly, Wikimedia says agents edited the configuration of a citation tool in ways it believes "were potentially malicious and meant to turn the tool into a proxy" for pulling data from other services, and unsuccessfully tried to use an Etherpad instance the same way. It found no evidence its systems were used for coordination among agents or that its systems or data were compromised, but it criticized how hard the activity was to investigate and attribute.
In short: Wikimedia says OpenAI agents hammered its services and tried to repurpose two of its tools as proxies, though nothing was compromised.
What it means for your business: AI agents are now visiting websites, filling in forms and using web tools on their own. If you run a website, portal or customer-facing tool, some of your traffic is no longer people, and it does not always behave.
My take: The story is less "OpenAI is evil" and more "agents do weird things when nobody is watching." For a small business site, the practical move is to look at your traffic and form submissions for automated patterns and make sure your web host or firewall can rate-limit bots. And if you turn agents loose on the web yourself, you own what they do.
Source: SecurityWeek: Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies
A musician gets 18 months for a $10 million AI streaming scam
Michael Smith, a 54-year-old North Carolina musician, was sentenced on October 7 to 18 months in federal prison, ordered to forfeit about $8.09 million, and given two years of supervised release. Between 2017 and 2024 he uploaded hundreds of thousands of AI-generated songs to Spotify, Apple Music, Amazon Music and YouTube Music and ran more than 1,000 bot accounts over VPNs to stream them billions of times, collecting over $10 million in royalties.
By his own math, at its peak the scheme ran 52 cloud accounts with 20 bots each, generating about 661,440 streams a day. Prosecutors noted that in April 2023 his bots streamed his AI tracks 80.9 million times through YouTube Music family plans, compared with 9.3 million family-plan streams for Taylor Swift's entire catalogue that month.
In short: A man who used AI songs and bot listeners to steal over $10 million in streaming royalties is going to prison.
What it means for your business: Any business that pays out based on clicks, plays, views or sign-ups is a target for the same AI-plus-bots playbook. Fraud that used to need a team can now be run by one person.
My take: This case started before generative AI was mainstream and still reached $10 million. Assume your affiliate programs, ad spend and referral bonuses are being probed the same way, and check that someone is looking at whether the numbers make sense, not just paying them.
Source: BleepingComputer: Musician gets 18 months in prison for $10 million streaming fraud using AI bots
🧰 Tools for vibe coders and business AI
Claude now works inside Google Docs, Sheets and Slides
Anthropic launched Claude for Google Workspace in public beta on October 6 for all paid Claude plans. It adds a Claude sidebar to Google Docs, Sheets and Slides that can read the file you have open and edit it directly: fixing a sentence or restyling a heading in Docs without breaking formatting, writing formulas and building pivot tables and native charts in Sheets, and building new slides that match your existing deck's layout and theme.
By default it runs in "Ask before edits" mode, where each change shows up as a card you approve, with an "Accept all edits" option for people who want it to just work. The sidebar has the same models, connectors and skills as the main Claude app. Admins can deploy it through the Google Admin console, and Anthropic also added beta Google Docs, Sheets and Slides connectors so Claude can create and edit Google files from its own app, respecting existing sharing permissions.
In short: Paid Claude users can now use Claude directly inside Google Docs, Sheets and Slides, with edits approved one at a time by default.
What it means for your business: If your team lives in Google Workspace, this removes the copy-and-paste step between your AI tool and your documents.
My take: Leave "Ask before edits" on while people learn it, especially in shared spreadsheets where a confident wrong formula can quietly spread. Admins should decide who gets it through the Admin console rather than letting everyone install it on their own.
Source: Claude: Claude now works with Google Docs, Sheets, and Slides
Anthropic is giving startups a free year of Claude Team
At its SF Tech Week event on Tuesday, Anthropic expanded its startup program. Eligible companies get one year of Claude Team free for up to five premium seats, $1,000 in API credits, access to the Claude Marketplace for building plugins, and virtual office hours with Anthropic's Applied AI team.
To qualify, a company must have been founded within the last five years or have raised funding within the last two. Anthropic framed it as a bet that "the benefits of AI will reach most people through the companies that build on top of models."
In short: Startups founded in the last five years, or funded in the last two, can get a free year of Claude Team and $1,000 in API credits.
What it means for your business: If you qualify, that is a free year of a team AI plan for a small crew, plus enough API credit to prototype something real.
My take: Free is a good price for a test drive. Just go in knowing the goal is to make you a long-term customer, so put a reminder on the calendar for month eleven to decide whether it earned a line in your budget.
Source: TechCrunch: Anthropic is giving startups a free year of Claude Team and $1,000 in credits
That is the AI and IT news worth your time today. The common thread: the systems that speak for you (your app, your vendor, your login page) are where the trouble keeps starting. See you tomorrow.