This week’s incidents all involve data held by institutions people cannot choose. An Arizona court breach exposed Social Security numbers alongside foster care reports and protective order records. Italy’s largest private banking group wired away more than $100 million after a cloned voice confirmed the instruction. And Poland is now investigating three separate attacks on its healthcare sector. Here’s a closer look at this week’s top cybersecurity headlines.

The Arizona Supreme Court has confirmed that attackers copied more than 270,000 court records after an employee clicked a malicious link in a phishing email. Chief Justice Ann Scott Timmer said IT staff found the intrusion and stopped it within two hours, but data had already been taken. The copied files include names and Social Security numbers for around 1.3 million people referred to the statewide FARE programme for court-ordered debts accrued over 30 years, plus more than 150,000 Foster Care Review Board recommendation reports dating back to 2010, and protective order information. The court says the reports contain no addresses or phone numbers, that no juror, witness or employee data was affected, and that the compressed backup format may make the data unreadable. The FBI, Homeland Security and Arizona DPS are investigating. AZPoint, the state’s protective order portal, was not compromised.
Experts note the data came from backups kept to recover from destructive attacks. Recovery infrastructure needs the same access controls, encryption and monitoring applied to production systems.
Source: KJZZ, KTAR, Arizona’s Family, Malwarebytes
Fideuram, Intesa Sanpaolo Private Banking, Italy’s largest private banking group with roughly $513 billion under management, was tricked into wiring more than $100 million abroad in February 2026. The attack worked through sequence rather than a single message. Then chairman Paolo Molesini received a WhatsApp message appearing to come from Intesa Sanpaolo chief executive Carlo Messina, asking for help with an urgent overseas transaction. He was then contacted by someone posing as a senior partner at a prominent law firm, who used AI to clone the lawyer’s voice and confirm the instruction as authentic. Molesini arranged a series of transfers through the finance department, mostly to accounts in mainland China and Hong Kong. Around $60 million was recovered with help from law enforcement in China, Portugal and Italy. Roughly $40 million remains missing, apparently converted into cryptocurrency. Molesini stepped down the following month.
Experts stress that a second confirmation is only a control if it reaches a contact sourced independently of the original request. Voice is no longer an authentication factor.
Poland’s national cybersecurity institute NASK is analysing attacks on three healthcare organisations: software vendors Qbusoft and MyDr, and private provider Enel-Med. At Qbusoft, which develops the Medyc records platform, an attacker exploited an SQL injection vulnerability in late August and moved an encrypted database archive out of the company’s systems, detected overnight on 9 September. Confirmed stolen data covers names, PESEL national identification numbers, addresses, phone numbers and email addresses, with Polish security publications reporting the breach may affect around 5 million people. The government said in August that the earlier MyDr incident could affect about 18.8 million people across more than 12,000 facilities. Digital Affairs Minister Krzysztof Gawkowski said Qbusoft failed to notify CERT Polska as required; Qbusoft says it reported to the data protection office, police and several agencies on 9 September.
Experts stress that SQL injection in a platform processing national identifiers is a procurement failure as much as an engineering one. Vendor assessments should require evidence of security testing, not assurances.
Source: The Record, Polskie Radio, InfoRiskToday
Conclusion
None of this week’s victims chose the systems holding their data. People paying court fines do not select the court, children in foster care do not pick the board reviewing their cases, and patients do not choose their clinic’s software vendor. Where consent is absent, the obligation sits entirely with the institution.