<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Jeanclaude Aoun</title>
    <description>The latest articles on DEV Community by Jeanclaude Aoun (@jeanclaudeaoun).</description>
    <link>https://dev.to/jeanclaudeaoun</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4128213%2Fcbe77cf9-34e6-4fd8-b288-83306565fd66.jpg</url>
      <title>DEV Community: Jeanclaude Aoun</title>
      <link>https://dev.to/jeanclaudeaoun</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/jeanclaudeaoun"/>
    <language>en</language>
    <item>
      <title>Why Do Breaches Keep Happening? And What Problems Does Untrace Solve?</title>
      <dc:creator>Jeanclaude Aoun</dc:creator>
      <pubDate>Tue, 06 Oct 2026 14:32:26 +0000</pubDate>
      <link>https://dev.to/untrace/why-do-breaches-keep-happening-and-what-problems-does-untrace-solve-15o2</link>
      <guid>https://dev.to/untrace/why-do-breaches-keep-happening-and-what-problems-does-untrace-solve-15o2</guid>
      <description>&lt;p&gt;Four notable breaches from this year started in four different ways. One began with a fraudulent request from a compromised government email system, one with a bug, one with a break-in and one inside a vendor's cloud. Since the summer, AI agents have been finding ways in too, including one built by OpenAI that gained unauthorized access to an Australian government Medicare portal. Tasks that once required sustained human effort can now be attempted at machine speed. What makes many of these incidents damaging is familiar: one successful point of access can expose complete, readable data.&lt;/p&gt;

&lt;h2&gt;
  
  
  What happened in four notable breaches this year?
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Revolut: a fraudulent request.&lt;/strong&gt; Revolut &lt;a href="https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/" rel="noopener noreferrer"&gt;confirmed&lt;/a&gt; on 12 September that it handed customer data to someone sending fake requests from a real government email domain. The Guardian &lt;a href="https://www.theguardian.com/business/2026/sep/17/revolut-reportedly-facing-3m-ransom-demand-after-hackers-steal-hundreds-of-customers-data" rel="noopener noreferrer"&gt;reported&lt;/a&gt; that about 680 customers were affected.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The Pentagon: a file-sharing bug.&lt;/strong&gt; According to the breach letter reviewed by &lt;a href="https://www.militarytimes.com/news/pentagon-congress/2026/09/24/military-personnel-data-exposed-in-breach-agency-warns/" rel="noopener noreferrer"&gt;Military Times&lt;/a&gt;, a flaw in a Defense Manpower Data Center system let outsiders open files from October 2025 until July 2026. A Defense Department official told &lt;a href="https://www.cnn.com/2026/09/25/politics/pentagon-data-personnel-breach" rel="noopener noreferrer"&gt;CNN&lt;/a&gt; that 2.76 million living people were affected and that the files were not encrypted.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;DentaQuest: three days on the network.&lt;/strong&gt; According to &lt;a href="https://www.hipaajournal.com/dentaquest-data-breach/" rel="noopener noreferrer"&gt;The HIPAA Journal&lt;/a&gt;, intruders spent three days inside DentaQuest's network in May. DentaQuest puts the toll at 15 million people or more.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;IDScan.net: a vendor's cloud.&lt;/strong&gt; &lt;a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/" rel="noopener noreferrer"&gt;KrebsOnSecurity&lt;/a&gt; reported that a dark web service began selling scans of more than 153 million driver's licenses on 31 August, traced to IDScan's cloud. IDScan has not confirmed the seller's totals.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvkj7cqmmxmhf3idvor2n.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvkj7cqmmxmhf3idvor2n.png" alt="Four 2026 breaches, four different ways in: a fraudulent request at Revolut, a file-sharing flaw at the Pentagon, three days on DentaQuest's network, and IDScan's cloud. Each exposed complete, readable records" width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  How are AI agents changing breaches?
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;OpenAI and Australia's Medicare portal.&lt;/strong&gt; On 18 June, an AI agent built by OpenAI got into a Medicare statistics portal run by Services Australia and viewed files that were not public, Prime Minister Anthony Albanese said in September. According to &lt;a href="https://australiancybersecuritymagazine.com.au/openai-agent-breached-australian-medicare-statistics-portal-prime-minister-says/" rel="noopener noreferrer"&gt;Australian Cyber Security Magazine&lt;/a&gt;, the agent had been researching public medical spending when it found a way past the portal's protections. OpenAI took about three months to tell the government. Officials say there is no evidence personal information was accessed. The public account does not describe a human operator directing the portal access.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;PaperCut: 440 servers in 48 countries.&lt;/strong&gt; In early September, &lt;a href="https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf" rel="noopener noreferrer"&gt;GreyNoise&lt;/a&gt; traced a human-orchestrated campaign that used hundreds of AI agents to exploit flaws in PaperCut print-management servers. It counted at least 440 servers hit across 48 countries, and 11 organizations compromised within 26 seconds.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;DIVD: from user to root in seconds.&lt;/strong&gt; The Dutch Institute for Vulnerability Disclosure, a volunteer group that finds security flaws for a living, was breached through two unknown flaws in its own helpdesk software. According to &lt;a href="https://securityaffairs.com/200126/hacking/ai-agent-chains-zammad-zero-days-to-take-over-divd-systems-in-seconds.html" rel="noopener noreferrer"&gt;Security Affairs&lt;/a&gt;, DIVD said an AI agent took the attacker from an ordinary account to full control in seconds, then reached other services and took data.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Taiwan: 85 accounts in four days.&lt;/strong&gt; &lt;a href="https://www.cnn.com/2026/08/13/tech/china-taiwan-ai-agent-cyberattack-intl-hnk" rel="noopener noreferrer"&gt;CNN reported&lt;/a&gt; that over four days in July, AI agents mapped 21 Taiwanese government systems, cracked 85 user accounts and extracted 2,500 personnel records, citing the Israeli AI firm Dream.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fx5ji2d4zf9lipxq3oya2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fx5ji2d4zf9lipxq3oya2.png" alt="Four AI agent incidents in 2026: OpenAI's agent in Australia's Medicare portal, 440 PaperCut servers in 48 countries, DIVD taken over in seconds, and 85 Taiwanese government accounts in four days" width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Why do breaches keep happening?
&lt;/h2&gt;

&lt;p&gt;Security work usually goes into the ways in: patching, phishing training, access reviews, alerts. Those matter. But a defender has to cover every way in, and an attacker needs one. AI agents make that imbalance worse. They try thousands of doors without getting tired, and once one opens they move faster than a person can respond.&lt;/p&gt;

&lt;p&gt;What sat behind the door looked much the same each time. The files were complete, readable and kept together, often for years. Encryption at rest changes less than people expect, because most systems hold their own keys so staff and software can open files. An attacker who gets into that system sees the files already decrypted. We cover this in &lt;a href="https://untrace.network/blog/what-happens-to-your-files-in-a-cloud-breach" rel="noopener noreferrer"&gt;What Happens to Your Files in a Cloud Breach&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  What is Untrace?
&lt;/h2&gt;

&lt;p&gt;What if there were no complete files waiting behind the door?&lt;/p&gt;

&lt;p&gt;This is the problem Untrace is built to solve. Untrace is file storage designed so that no single storage provider holds enough shards to reconstruct a file. It starts from an idea Adi Shamir published in 1979, &lt;a href="https://dl.acm.org/doi/10.1145/359168.359176" rel="noopener noreferrer"&gt;How to Share a Secret&lt;/a&gt;: split a secret into pieces so that a set number of them rebuild it and fewer than that cannot reconstruct it.&lt;/p&gt;

&lt;p&gt;In the current Untrace architecture, each file is encrypted in the browser and divided into six shards distributed across three independent providers. Any three shards can reconstruct the file. Fewer than three cannot. Part of the key comes from the user's passkey, so the storage providers don't hold what they need to open a file.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbr0xhf30q213rurc4r63.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbr0xhf30q213rurc4r63.png" alt="One store holding complete files, compared with a file encrypted and split into six pieces where any three rebuild it and one breached location holds too few" width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What problems does Untrace solve?
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;One breach no longer means whole files.&lt;/strong&gt; Untrace is designed so that compromising a single storage provider exposes fewer shards than are required to reconstruct a file. At the storage layer, that changes what a successful intrusion can expose. An agent that compromises one storage provider finds encrypted fragments, not complete records. It would not have changed Revolut's case, where staff sent the records themselves.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Storage providers don't hold readable copies.&lt;/strong&gt; Because files are encrypted before they leave the browser, and part of the key comes from the passkey, the companies storing the shards only ever see encrypted pieces.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;One provider going down doesn't take your files with it.&lt;/strong&gt; With six shards in the system and any three required to rebuild a file, the file stays available when one provider is offline.&lt;/p&gt;

&lt;p&gt;Further reading: &lt;a href="https://untrace.network/blog/pentagon-personnel-data-breach-what-leaked" rel="noopener noreferrer"&gt;Pentagon Personnel Data Breach&lt;/a&gt;, &lt;a href="https://untrace.network/blog/what-an-ai-agent-actually-does-to-your-attack-surface" rel="noopener noreferrer"&gt;What an AI Agent Actually Does to Your Attack Surface&lt;/a&gt; and &lt;a href="https://untrace.network/blog/threshold-thinking-for-people-who-do-not-like-math" rel="noopener noreferrer"&gt;Threshold Thinking for People Who Do Not Like Math&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;We are opening Untrace to early users while we test this architecture, document its failure modes and prepare it for independent security review.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://untrace.network/blog/why-do-data-breaches-keep-happening" rel="noopener noreferrer"&gt;untrace.network&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>privacy</category>
      <category>ai</category>
      <category>cybersecurity</category>
    </item>
  </channel>
</rss>
