Ransomware ready? Take the 3-minute assessment→

Satine Sentinel: October 2, 2026

A crypto exchange lost $387.5 million through the security products it had bought to protect itself, and the attackers had been inside for 24 days before the first transfer. A health system learned on August 4 that a contractor-run legacy system holding imaging records may have been exposed, and began notifying patients 56 days later. A Mississippi city of about 20,000 people disconnected its internet on Thursday, delaying in-person payments at a water and gas office that serves more than 10,000 accounts.

This week: three incidents where the damage landed in a system that sits beside the core operation rather than inside it. Bitget’s loss ran through third-party security appliances, IU Health’s through a vendor-managed legacy system, and Vicksburg’s through the back-office computers that bill a city’s utility customers. The first two entered through tools and contractors the organization did not run itself. Vicksburg has not said how attackers got in.


Update: Bitget Loses $387.5 Million Through Third-Party Security Products

What happened: Attackers moved $387.5 million out of Bitget’s hot and warm wallets over nearly three hours beginning at about 18:31 UTC on September 24. Bitget first estimated the loss at $351.6 million, then raised it on September 25 after counting Zcash and TRON assets. On September 30, forensic findings from Mandiant and SlowMist, released through Bitget, showed that the intrusion began on August 31 with a zero-day flaw in a third-party security product, nearly four weeks before any funds moved.

Note on timing: the theft and first disclosure came on September 24, one day before this window opened. We are covering it now because the September 30 forensic findings and the October 2 recovery update are material new developments, including a root cause far more specific than the “backend system” the CEO described at first.

Technical details that matter:

Why critical institutions should care: Bitget’s security tooling was both the way in and the staging ground. Appliances that hold stored credentials and sit in a privileged network position are what a patient attacker wants, because everything around them trusts them and almost nothing watches them. Twenty-four days passed between the first malicious activity in the logs and the first transfer, and the theft then passed through approval flows that treated forged orders as routine. The financial cushion mattered too: Bitget told CNBC it refilled its protection fund to $300 million using its own capital. Most institutions have no reserve like that. For any bank, credit union, or payments firm, the question is not whether its security vendors are good. It is who watches the vendors’ products once they are inside the network.

Key sources:


IU Health Vendor Breach Exposes Southern Indiana Imaging Records

What happened: Indiana University Health announced on September 29 that unauthorized access had occurred on a legacy system managed by its IT vendor, AME Group. The system held radiology files from an imaging center serving Southern Indiana patients. IU Health says it learned on August 4 that AME may have been exposed to a previously unknown software vulnerability, then reviewed the vendor-managed system itself and confirmed the access. Patient notifications began September 29, 56 days after the vendor warning.

Technical details that matter:

Why critical institutions should care: The system that was breached was not the system IU Health’s security program was built to defend. It was an old, isolated, vendor-run box, the kind of asset that falls off inventories. Isolation is a claim, not a control: IU Health’s network was untouched and patient records were exposed anyway. The timeline is the second lesson. Eight weeks passed between the first vendor warning and the first patient notice, and the public still does not know how many people are affected. Healthcare leaders should ask which legacy and vendor-hosted systems still hold patient data, what their contracts require the vendor to tell them about a suspected exposure, and how fast.

Key sources:


City of Vicksburg, Mississippi, Ransomware Attack

What happened: Mayor Willis Thompson said a ransomware attack hit the City of Vicksburg on Thursday, October 1, forcing a shutdown of city computer systems and a disconnection of its internet operations. 911, police, fire, and utility service remain operational, but in-person utility payments may be delayed. The city says no one will face penalties or service shutoffs while its systems are offline, and it is working with the FBI, the Department of Homeland Security, state officials, and outside cybersecurity specialists.

Technical details that matter:

Why critical institutions should care: The reporting does not indicate that water treatment or distribution controls were touched, and the city says utility service continues. That is the point. A utility can keep water flowing and still lose the ability to bill, which becomes a cash problem and a data problem within weeks. Customer billing records combine names, addresses, and account details for thousands of households, and municipalities often run them on thin IT staffing. Leaders in government and utilities should plan for the day the physical service works and the paperwork does not, including what to tell customers about late fees and shutoffs. Vicksburg answered that question on day one, which is worth copying.

Key sources:


The Pattern this Week

Three organizations, three different back doors, one shared habit: each trusted a system it did not closely watch. Bitget trusted security appliances inside its own network, and an attacker lived in them for 24 days. IU Health trusted a contractor to protect a legacy system, and the first warning arrived in early August while patients heard in late September. Vicksburg has not said how attackers got in, but the damage landed in the back office that bills thousands of utility customers, a system nobody puts on a risk slide until it stops.

None of these were the crown jewels on paper. All of them became the crown jewels in practice, because they connected to money, patient records, and customer accounts. The defender’s problem this week is an inventory of trust: the list of things your organization depends on but does not operate, and the name of the person watching each one.

See you next week!


What Your Business Can Do This Week

  1. Ask your IT leader or provider for a list of every security product inside your network that your own team did not build, such as firewalls, remote access gateways, and monitoring consoles. For each one, ask who has administrator access and who reviews its logs. Then ask the question Bitget could not answer in time: if one of these products were compromised today, how would we know?
  2. If your organization moves money, confirm that a payment cannot be approved by internal systems alone. Unusual or high-value transfers should need confirmation from a person or a separate system outside the environment that initiated them. Bitget’s own approval process accepted forged orders as valid.
  3. Make a list of old systems and vendor-managed systems that still hold sensitive data, including any described as isolated. For each, find the contract language on how quickly the vendor must tell you about a suspected problem, and ask for a written commitment on notification timing and on the logs you can see.
  4. Rehearse two weeks of billing, payments, and customer service with no computers. Confirm that offline copies of customer account lists exist, decide in advance what you will tell customers about late fees and service shutoffs, and name who has authority to disconnect the network.

Final CTA Section
GET STARTED

Ready to Strengthen Your Defenses?

Whether you need to test your security posture, respond to an active incident, or prepare your team for the worst: we’re ready to help.

📍 Based in Atlanta | Serving Nationwide

Discover more from Satine Technologies

Subscribe now to keep reading and get access to the full archive.

Continue reading