CyberHood Weekly Cyber Watch

Weekly Cyber Watch

A concise intelligence roundup covering major cyber incidents, vulnerabilities, breaches and ransomware activity observed during the week.

Cyber Intelligence
What happened this week?
Key cybersecurity developments from 25 September through 1 October 2026.

Bitget says $387.5 million crypto theft began with zero-days in third-party security products

Short Description

Cryptocurrency exchange Bitget disclosed new forensic findings about its 24 September theft, saying attackers compromised third-party security appliances using previously unknown vulnerabilities before reaching its wallet environment. Bitget puts the affected funds at approximately $387.5 million and says its cold wallets were unaffected. Investigations involving Mandiant and SlowMist identified the attack path, while recovery efforts and phased withdrawal restoration continued.

Safety Takeaway

Organisations should treat security appliances as high-value attack surfaces: patch them rapidly, restrict administrative access, monitor them for compromise and avoid assuming a “security product” is itself inherently secure.

This Week’s Watchlist
Weekly Snapshot

Five significant cyber incidents and vulnerabilities highlighted in this week’s CyberHood monitoring.

Cyber Intelligence
What happened this week?
Key cybersecurity developments from 25 September through 1 October 2026.

Bitget says $387.5 million crypto theft began with zero-days in third-party security products

Short Description

Cryptocurrency exchange Bitget disclosed new forensic findings about its 24 September theft, saying attackers compromised third-party security appliances using previously unknown vulnerabilities before reaching its wallet environment. Bitget puts the affected funds at approximately $387.5 million and says its cold wallets were unaffected. Investigations involving Mandiant and SlowMist identified the attack path, while recovery efforts and phased withdrawal restoration continued.

SUSPICIOUS MESSAGE — TRAINING SIMULATION

From: National Student Scholarship Desk <scholarship.support@gmail.com>
Subject: FINAL CONFIRMATION REQUIRED — Scholarship Expires Today!

Dear Aanya,

Your profile has been shortlisted for a ₹50,000 scholarship. To release your funds today, complete verification within 30 minutes.

Click here to confirm your award: [Verify Scholarship Now]

Please submit your college login ID, password, date of birth, bank account details, and the OTP sent to your mobile. Failure to act immediately will result in permanent cancellation.

This offer is confidential. Do not contact your college office, as that may delay your payment.

Regards,
Scholarship Processing Team

The pressure builds

Aanya notices that two classmates have forwarded a similar message in a group chat. One says, “It looks official—just do it quickly!” Another student says the scholarship portal normally uses the college website. Aanya has only a few minutes before class, and the countdown in the message makes her anxious.

Your mission

You are part of the college’s Cyber Safety Response Team. Help Aanya decide what to do before the deadline. Read the evidence, identify the warning signs, and choose a safe verification route.

MISSION 1 : FIND THE RED FLAGS

Task

Identify at least five warning signs in the message. For each one, explain why it is suspicious.

  • Sender uses a generic email address rather than a verifiable official domain
  • Urgent deadline and threat of losing the scholarship
  • Request for password and OTP
  • Request for bank and personal information through an unsolicited message
  • Link destination is hidden or not independently verified
  • Message discourages contacting the college
  • Unclear organisation name and no verifiable application reference
  • Promise of a large award without a clear, verifiable application process

MISSION 2: CHOOSE YOUR NEXT MOVE

Decision point

Aanya has not clicked the link. What should she do next? Choose one response.

  • Option A – Click the link and fill in the form quickly, because the scholarship may be genuine.
  • Option B – Reply to the sender asking whether the message is real, then share details if they confirm.
  • Option C – Do not click or reply. Open the college’s official website or contact the scholarship/college office using a known, independently verified contact method.
  • Option D – Forward the message to classmates so they can decide whether to apply.
MISSION 3: THE TWIST

New evidence

Aanya previews the link without opening it and sees a web address that does not match the college or a recognised scholarship portal. The sender then messages her again: “Only 5 minutes left. Send your OTP now to reserve your funds.”
Question

What does this new evidence suggest? What should Aanya do if she has already clicked the link or entered information?

DEBRIEF: WHAT THE INVESTIGATION REVEALS

Likely explanation

The message displays common signs of phishing and social engineering. It uses a tempting reward, urgency, a request for sensitive information, an unverified link, and a warning not to verify independently. These clues strongly suggest an attempt to steal credentials or personal/financial information. A message’s appearance or a classmate’s forward does not prove that it is legitimate.

Safe response

Aanya should avoid the link, not reply, and verify the scholarship through the college’s official website or a contact method obtained independently. She can report the message to the college’s IT/help desk and the email or messaging platform. If she has entered a password, she should change it immediately using the genuine website, change it anywhere else it was reused, and enable multi-factor authentication where available. If she shared an OTP or financial information, she should contact the relevant bank/service provider promptly and follow its account-protection guidance.

Remember

Pause. Inspect. Verify independently. Never share passwords or OTPs in response to unsolicited messages.

ASSESSMENT (5 MARKS)

Q1 — Red flags (2 marks)

Name any four warning signs in the scholarship message. (0.5 mark each, up to 2 marks)

Q2 — Safe verification (1 mark)

State one safe way to verify whether the scholarship is genuine.

Q3 — Sensitive information (1 mark)
Why should Aanya never share her password or OTP with the sender?

Q4 — Incident response (1 mark)

What is one immediate action Aanya should take if she has already entered her password?

SUBMIT YOUR INVESTIGATION — 5 MARKS
Enter your answers below, then select Check my answers to see an immediate score and feedback.

Privacy note: This standalone webpage grades answers in your browser only. It does not send answers to your teacher, save a class record, or identify who submitted. If your teacher needs to collect grades, connect this activity to a college LMS or an online form.

-------------- Form will be place here ------------