The September Threat Landscape
September 2025 proved to be a particularly challenging month for cybersecurity professionals and organizations worldwide. From ransomware attacks targeting healthcare providers to supply chain compromises affecting major corporations, the month highlighted the evolving and persistent threat landscape. The attacks demonstrated that no sector is immune, with victims ranging from automotive manufacturers to tech companies, healthcare providers, and government agencies.
What’s particularly concerning about this month’s breaches is the sophistication of attack vectors employed, including third-party vendor compromises, ransomware campaigns, and social engineering tactics. These incidents serve as a stark reminder that vendor risk management must be a top priority for organizations of all sizes.
Major Breach Incidents
1. Jaguar Land Rover (JLR) – Major Manufacturing Disruption
Date: Early September 2025
Impact: Production facilities and retail operations severely disrupted
Data Compromised: Internal systems, manufacturing data, and operations
Attack Method: Cyberattack targeting IT and manufacturing systems
Jaguar Land Rover experienced a significant cyberattack that forced shutdowns of global IT and manufacturing systems during peak production season. The attack disrupted both production lines and retail operations across multiple facilities. Workers at the Halewood plant near Liverpool were sent home as systems went offline. The company extended production delays into October, demonstrating the far-reaching impact of the incident.
The attack occurred during a critical period for the automotive industry, amplifying the business impact. JLR’s incident highlights the vulnerability of just-in-time manufacturing systems to cyber disruptions and the cascading effects on supply chains.
2. Salesloft Drift – Supply Chain Breach
Date: August 2025 (disclosed late August–early September 2025)
Impact: Multiple major tech companies affected including Cloudflare, Palo Alto Networks
Data Compromised: Salesforce authentication tokens, business contact information, sales account data
Attack Method: Third-party integration compromise between Drift chat agent and Salesforce
An advanced threat actor known as GRUB1 exploited the integration between Salesloft’s Drift chat platform and Salesforce, gaining unauthorized access to multiple companies’ Salesforce environments. The breach affected numerous high-profile organizations, with Cloudflare confirming that 104 API tokens were compromised.
The attack demonstrated the risks inherent in third-party integrations, where a vulnerability in one vendor’s system can cascade across multiple organizations. Companies using the Drift-Salesforce integration found their business contact data and sales information exposed through this supply chain attack.
Palo Alto Networks investigation revealed that exfiltrated data included business contact information and sales account details, though no customer data or product information was affected.
3. European Airports Ransomware Attack
Date: September 20-22, 2025
Impact: Major disruptions at Europe’s busiest airports including Brussels, Frankfurt, London, with cancelled flights and fallback manual check-ins.
Systems Affected: Automated check-in / boarding systems provided by Collins Aerospace
Attack Method: Ransomware via third-party service provider
A coordinated ransomware attack targeting Collins Aerospace, a key provider of passenger check-in and boarding systems, caused widespread disruptions across several major European airports. The EU’s aviation safety agency confirmed the incident involved ransomware, forcing airports to resort to manual processes such as handwritten boarding passes and tablets. Dozens of flights were cancelled or delayed, including 60 at Brussels alone on September 22, and the disruptions extended through the weekend.
The incident highlighted the vulnerability of critical infrastructure when shared service providers are compromised, underscoring the cascading impact such attacks can have across multiple countries during peak travel periods.
4. South Korean Telecom Providers – Data Breach
Date: Late September 2025
Impact: Three major cellphone carriers affected
Data Compromised: Customer personal and service information
Attack Method: Series of data breaches across multiple providers
South Korean authorities launched investigations into data breach reports affecting three of the country’s largest cellphone service providers. The coordinated nature of the breaches raised concerns about potential targeted attacks on telecommunications infrastructure.
The incident affected millions of customers across multiple carriers, compromising personal information and service records. The breach highlighted vulnerabilities in telecom infrastructure and the attractiveness of these providers as targets for cybercriminals seeking large datasets of personal information.
5. Bridgestone – Manufacturing Disruption
Date: September 2025
Impact: North American manufacturing facilities disrupted
Data Compromised: Bridgestone believes no customer or company data was compromised
Attack Method: Cyberattack on production systems
Bridgestone Americas, the North American arm of the world’s largest tire manufacturer, is investigating a cyberattack that disrupted operations at several manufacturing facilities in South Carolina and Quebec. The company says its quick response contained the incident early, preventing customer data theft or major network compromise, while teams work to limit supply chain impacts. No ransomware group has claimed responsibility, and the type of attack hasn’t been confirmed. This follows a 2022 LockBit breach that exposed sensitive company data.
The attack on Bridgestone’s manufacturing systems demonstrated how cyber incidents can disrupt physical production, affecting supply chains and potentially causing shortages. As a major supplier to the automotive industry, the ripple effects extended beyond the company itself.
6. Healthcare Sector – Multiple Incidents
Date: Throughout September 2025
Impact: Various healthcare providers including blood centers, eye care facilities
Data Compromised: Patient records, Social Security numbers, medical information
Attack Method: Ransomware attacks and data breaches
September saw multiple healthcare organizations fall victim to cyberattacks:
New York Blood Center: Disclosed that thousands had data leaked following a January ransomware attack, with the full scope revealed in September 2025
Retina Group of Florida: 153,429 patients affected by data breach compromising personal and medical information
Medical Associates of Brevard: Experienced ransomware attack affecting patient data
Pensacola Hospitalist Physicians: Data breach affecting patient information
These healthcare breaches followed a concerning trend of attackers targeting medical providers, where sensitive patient data combined with critical operational needs creates pressure to pay ransoms quickly.
7. Prosper – Financial Services Data Breach
Date: September 2025
Impact: Financial services customers affected
Data Compromised: Although there is no evidence of customer accounts or funds being compromised, the Prosper data breach involved access to confidential, proprietary, and personal data, including Social Security numbers.
Attack Method: Data breach
Financial services company Prosper disclosed a data breach affecting customer information including Social Security numbers. The incident prompted legal action and investigations into the company’s data protection practices.
The breach highlighted the critical importance of protecting financial data and the potential legal consequences when organizations fail to adequately secure sensitive customer information.
8. The Job Shop – Massive Data Exposure
Date: September 2025
Impact: 135GB of sensitive employment information exposed
Data Compromised: Employment records, personal information
Attack Method: Third-party IT breach
Nationwide staffing and employment agency The Job Shop experienced a major data breach when its third-party IT provider was compromised. The breach exposed 135GB of sensitive information including employment records and personal data.
The incident demonstrated how smaller organizations can suffer significant data exposures through their technology partners, affecting both employees and job seekers in their databases.
9. Moinian Group – Real Estate Breach
Date: September 2025
Impact: Real estate company and tenant data
Data Compromised: Business and potentially tenant information
Attack Method: Data breach
The Moinian Group, a major real estate company, experienced a data breach prompting lawsuit investigations. The incident affected business operations and potentially exposed tenant information.
Real estate companies hold significant amounts of personal and financial information about tenants and property owners, making them attractive targets for cybercriminals.
10. Multiple Smaller Incidents
Date: Throughout September 2025
Several other organizations reported breaches during September:
Waterford Surgical Center: Michigan hospitalist group suffered data breach
Wytech Industries: Medical wire manufacturer disclosed breach following ransomware attack
Tekni-Plex: Global packaging manufacturer experienced data breach affecting personal data
MoneyBlock (AOS): Online trading platform breach exposed Social Security numbers
These incidents demonstrate that organizations of all sizes remain targets, with attackers showing no preference based on company size or sector.
Connecting the Dots: Broader Trends
September 2025’s breach landscape reveals several critical trends that organizations must address:
1. Supply Chain Vulnerabilities Remain Critical
The Salesloft Drift incident exemplifies how third-party integrations create cascading risks. When attackers compromise a single vendor, they gain access to multiple downstream organizations. This supply chain attack model continues to be highly effective, as demonstrated by the widespread impact on companies like Cloudflare and Palo Alto Networks.
2. Ransomware Evolution Continues
Healthcare remains a prime target due to the critical nature of operations and valuable patient data. The airport systems attack demonstrated how ransomware can disrupt critical infrastructure beyond just data encryption, affecting physical operations and causing real-world chaos.
3. Manufacturing Sector Under Siege
Attacks on JLR and Bridgestone highlight the vulnerability of manufacturing systems. As these organizations increasingly integrate IT and operational technology (OT), the attack surface expands. Disruptions to manufacturing don’t just affect data—they halt production, impact supply chains, and create cascading economic effects.
4. Third-Party Risk Management is Non-Negotiable
Multiple incidents this month stemmed from third-party vendor compromises. Organizations can have robust internal security controls but remain vulnerable through their vendors, suppliers, and integration partners. Traditional vendor risk management approaches that rely on annual questionnaires and compliance certifications are insufficient.
The CloudVRM Solution
The breaches of September 2025 underscore a fundamental challenge in modern cybersecurity: how can organizations maintain continuous visibility into vendor security postures when threats evolve daily?
Why Traditional VRM Falls Short
Traditional vendor risk management programs suffer from critical limitations:
Point-in-time assessments that become outdated immediately
Self-reported data from vendors that may not reflect reality
Delayed visibility into security incidents and misconfigurations
Manual processes that can’t scale with growing vendor ecosystems
Lack of real-time alerts when vendor security postures degrade
CloudVRM: Real-Time Vendor Cloud Risk Monitoring
CloudVRM addresses these gaps with continuous, automated monitoring of vendor cloud infrastructure:
Key Capabilities:
Real-time monitoring across 300+ security domains
Automated verification of controls directly from vendor cloud environments
Instant alerts on misconfigurations, exposures, or breaches
Fast deployment – less than 20 minutes to connect a vendor
API-driven data collection eliminating reliance on vendor self-reporting
Acting as “Radar for Vendor Cloud Risk”
CloudVRM complements traditional VRM programs by providing continuous visibility. While traditional assessments offer snapshots, CloudVRM delivers ongoing surveillance, alerting security teams to emerging risks before they result in breaches.
In the wake of supply chain attacks like Salesloft Drift, organizations need real-time visibility into vendor security postures. CloudVRM enables this by monitoring vendor infrastructure continuously, detecting the types of misconfigurations and vulnerabilities that attackers exploit.
Learn More
The incidents of September 2025 demonstrate that vendor risk management can no longer be a periodic exercise. With CloudVRM’s continuous monitoring and automated verification, organizations can maintain persistent visibility into vendor security postures, enabling rapid response to emerging threats.
Contact us to learn how real-time vendor cloud risk monitoring can strengthen your security posture and prevent supply chain breaches.