Get a quote

Global Data Breaches and Cyber Attacks in September 2026 – At Least 252.8 Million Breached Records

09 October 2026

Blog

Monthly Data Breaches and Cyber Attacks

Our research found 40 publicly disclosed data breaches and cyber attacks in September 2026, with at least 252,804,563 records confirmed as breached. That total is a floor: it counts only figures confirmed by the organisation affected, a regulator or an independent researcher, and leaves out a further 164 million records that attackers have claimed. About 87% of the confirmed total comes from one exposed database in Vietnam.

Three headline figures for September 2026: 40 publicly disclosed incidents; 252.8 million confirmed records breached as a lower bound across 18 incidents; and 164.19 million claimed or estimated records across 5 incidents, excluded from the confirmed total.

 

Summary

  • Total number of incidents disclosed: 40
  • Total number of confirmed records breached (lower bound): 252,804,563, from 18 incidents

The number of breached records comprises those verified by the affected organisation, a regulator or independent researcher analysis.

It excludes the 5 incidents that rest on attacker claims and the 17 incidents with no figure at all, such as cryptocurrency thefts and attacks where the organisation has not said how many people were affected.

The units differ (accounts, individuals, records, email addresses) and are summed as reported. For Gyazo, we count the 23.62 million user records, not the 490 million image-metadata records that were also exposed.

Two large claims that are not in the total

Two attacker claims are large enough that, if verified, both would rank among the month’s five largest incidents. Neither organisation has confirmed the figure, so we have left them out of the confirmed total and the top five below, and summarise them here instead.

IDScan.net

  • Records affected: 153 million driver’s licence scans (claimed). IDScan has not said how many people were affected.
  • Data: Names, driver’s licence numbers and other government ID numbers; the marketplace listing also offers licence images and other ID documents.
  • Cause: Not disclosed. IDScan says an unauthorised third party accessed customer information in its cloud platform; a journalist traced authenticated samples to the company.
  • Status: Breach confirmed by the company in a notice dated 4 September. The record count is unconfirmed.

 

CenterPoint Energy

  • Records affected: 7.49 million customer records (claimed). CenterPoint has not confirmed a count.
  • Data: Claimed: names, phone numbers, email addresses, service and billing addresses, account and premise IDs, billing amounts and the last four digits of Social Security numbers. CenterPoint has confirmed only that personal information was taken.
  • Cause: CenterPoint says a third party obtained data through an external-facing system. The person who leaked the data says it was an API with no authentication or rate limiting; the company has not confirmed that.
  • Status: Breach confirmed in a Form 8-K filed on 14 September. The scope is under investigation.

Top five incidents by confirmed records affected

The five largest incidents publicly disclosed in September 2026, ranked by confirmed number of records (attacker claims are covered separately above):

Horizontal bar chart of the 5 largest incidents by number of records. The largest is Vietnam-linked APIS database (operator not identified) at 220.78 million records (confirmed). Every count shown is confirmed.

 

1. Vietnam-linked APIS database

  • Records affected: 220,783,700 travel records, not unique people (confirmed by independent researchers).
  • Data: Names, dates of birth, sex, nationality, passport or travel-document numbers and expiry dates, plus flight, seat and baggage details for people who travelled to, from or through Vietnam between 2017 and 2026.
  • Cause: An Elasticsearch database named ‘pax-info’ was reachable through two chained misconfigurations: a cloud path and default credentials.
  • Status: Confirmed exposure. Kinryū Labs found it on 3 June and it was secured on 8 June. There is no evidence that anyone copied the data, and the operator has not been identified.

2. Gyazo (Helpfeel)

  • Records affected: 23.62 million user records (confirmed). A further 490 million image-metadata records were also exposed and are not counted.
  • Data: Names or nicknames, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google single sign-on email addresses, and subscription and billing status. Payment data was not exposed.
  • Cause: An attacker exploited a vulnerability in Gyazo’s image-upload server on 11 September and ran commands on it.
  • Status: Confirmed by Helpfeel, Gyazo’s operator, on 16 September. No attacker has been named.

3. US Department of Defense (Defense Manpower Data Center)

  • Records affected: 3,054,000 people: 2.76 million living and 294,000 deceased (confirmed by the Department of Defense).
  • Data: Social Security numbers, occupational specialties and other military and civilian personnel details, all unencrypted.
  • Cause: A vulnerability in a Defense Manpower Data Center file-sharing system. Unauthorised users had access from October 2025 until the centre found and patched the flaw on 16 July 2026.
  • Status: Confirmed. Military Times reported the breach on 24 September, and defence officials confirmed the counts to CNN and ABC on 28 September; the notification letter is dated 18 September. The centre has not said who was responsible. Some outlets suggest up to 4 million people could be affected, but that figure is unverified.

4. Times Car (Park24)

  • Records affected: About 1.6 million accounts with identity documents confirmed leaked. The company’s stated maximum is 6.6 million accounts.
  • Data: Names, addresses, dates of birth, phone numbers, email addresses, driving licence details and identity documents. Passwords were stored in a non-restorable form and no card data was taken.
  • Cause: Unauthorised access to the Times Car web system, detected on 25 September. The company has not said how the attacker got in.
  • Status: Confirmed by Park24, the parent company, on 25 September. The investigation is continuing and the incident has been reported to Japan’s data protection regulator.

5. Mathspace

  • Records affected: 1,079,819 people: students, staff and parents or guardians in Australia and New Zealand (confirmed by Mathspace).
  • Data: User IDs, usernames, names, email addresses, country, time zone, user type, email-verification status, and last-active and login dates. No passwords, academic data or authentication tokens were exposed.
  • Cause: An unpatched vulnerability in Metabase, the self-hosted reporting software Mathspace uses. Metabase patched the flaw on 6 August; Mathspace’s process failed to escalate the advisory and it updated on 29 August. Attackers had access from 10 August and downloaded data on 27 August.
  • Status: Confirmed by Mathspace, which verified the breach on 3 September after reviewing access logs and began notifying schools on 4 September. No attacker has been named.

Trends in September 2026

This is our first monthly report since October 2025, so we’re making no month-on-month comparisons this time. However, several patterns stand out:

  • Claimed figures came to about 164 million records
    Five incidents rest on claimed figures, together about 164 million records: IDScan (153 million), CenterPoint (7.49 million), Veradigm (3.5 million), the Florida driver database (200,000) and the FBI jobs portal (a 5,000-record sample). Only 18 of the 40 incidents have a confirmed count.

Single stacked bar of 40 incidents: 18 with a confirmed record count, 5 with only a claimed or estimated figure and 17 with no known or applicable figure.

  • Third parties were the way in for six incidents
    IDScan, DriveWealth, BigCommerce through its Ribon apps, Veradigm, Brevo and Dropbox through Lenovo ID all involved a supplier or partner rather than the victim’s own systems. Another 7 incidents involved exploited vulnerabilities and the cause of 14 is still not public.

Bar chart, ranked from highest: Other/unknown (14); Vulnerability exploitation (7); Phishing/social engineering (4); Supply-chain/third-party (4); Insider/human error (3); Data extortion (3); Misconfiguration/exposure (2); Ransomware (2); Credential abuse (1).

  • Japan accounted for half of the Asia-Pacific total
    Asia-Pacific had 14 incidents, level with North America. Seven involved Japanese organisations (Gyazo, Times Car, the Digital Agency, Keio, Tokyo Metro, Seicomart and Benefit One), and five of those were disclosed between 25 and 30 September.

Bar chart, ranked from highest: North America (14); Asia-Pacific (14); Global (5); UK and Ireland (4); Europe (3).

  • AI tools appeared in three incident reports
    An OpenAI research agent reached non-public files on an Australian Medicare statistics portal; a Spanish organisation told its regulator that an AI agent ran an attack on its systems; and a Singapore retailer’s AI-written mailing script exposed 95,364 customers’ email addresses. Spain’s data protection agency and Singapore’s regulator each called theirs the first notification of its kind.
  • Cryptocurrency thefts have no record counts
    Bitget lost about US$387.5 million (revised up from US$351.6 million) and the Liquid Network about US$320 million, of which about US$47 million was not returned. We list both in the table but do not rank them.

Bar chart, ranked from highest: Government and public sector (8); Transport and logistics (5); Technology and SaaS (5); Healthcare (4); Education (3); Professional services (3); Energy and utilities (2); Crypto and DeFi (2).

Key vulnerabilities exploited

  • Unpatched software
    Mathspace’s self-hosted Metabase instance had a vulnerability disclosed on 6 August that went unactioned until 29 August; Japan’s Digital Agency was hit through a VPN flaw that had a patch available; the Pentagon’s Defense Manpower Data Center had a file-sharing system vulnerability that exposed unencrypted records for about nine months.
  • Zero-days
    Bimbo Bakeries says an Oracle E-Business Suite zero-day exposed files containing names and Social Security numbers; ShinyHunters claims a PeopleSoft zero-day gave it access to the FBI jobs portal, which the FBI has not confirmed (Mandiant reports renewed exploitation of CVE-2026-35273 in PeopleSoft); the Liquid Network lost funds to a bug in how Elements caches range-proof verifications.
  • Third-party credentials and keys
    A compromised application key held by the Ribon apps exposed BigCommerce shopper data; stolen vendor credentials reached a Veradigm API; a single sign-on flaw let an attacker into 138 Brevo accounts; and a Lenovo email-verification flaw let attackers into about 5,000 Dropbox accounts.
  • Stored, default and misconfigured credentials
    Florida’s DAVID database was reached with a police user’s credentials kept on a personal device; the Vietnamese passenger database accepted default credentials; Benefit One’s survey function showed other organisations’ employee data because of a configuration error.
  • Social engineering and impersonation
    Revolut released customer data to someone using a government agency’s email domain; DriveWealth, Astrana and Quinn Emanuel were each reached through social engineering, in Astrana’s case with a spoofed company phone number.

List of data breaches and cyber attacks disclosed in September 2026

Disclosure dateOrganisationCountrySectorIncident typeRecords affectedStatus
01-09-2026IDScan.netUSATechnology and SaaSSupply-chain/third-party153 million licence scans (claimed)Confirmed
01-09-2026NovocureUSAHealthcareData extortionMore than 1,400 patient recordsConfirmed
02-09-2026Dropbox (via Lenovo ID)USATechnology and SaaSSupply-chain/third-partyAbout 5,000 accountsConfirmed
03-09-2026P&O FerriesUKTransport and logisticsInsider/human errorNot disclosed (one sailing)Confirmed
03-09-2026Quinn Emanuel Urquhart & SullivanUSAProfessional servicesPhishing/social engineeringNot disclosedConfirmed
04-09-2026Bimbo Bakeries USAUSAManufacturingVulnerability exploitationNot disclosedConfirmed
04-09-2026Natural Resources WalesUKGovernment and public sectorInsider/human errorNot disclosed (staff employed 2013–2018)Confirmed
06-09-2026Liquid Network (Blockstream)Not statedCrypto and DeFiVulnerability exploitationn/a (about US$320m taken; about US$47m kept)Confirmed
06-09-2026MathspaceAustraliaEducationVulnerability exploitation1,079,819 peopleConfirmed
06-09-2026Weverse (HYBE)South KoreaMedia and entertainmentVulnerability exploitation422,584 accountsConfirmed
07-09-2026City of Everett, MassachusettsUSAGovernment and public sectorOther/unknownNot disclosedNo evidence of data theft
07-09-2026Gangnam Unni (Healing Paper)South KoreaHealthcareOther/unknown219,665 usersConfirmed
07-09-2026Springfield Public Schools (Massachusetts)USAEducationOther/unknownNot disclosedNo evidence of data theft
07-09-2026Stadtwerke LandsbergGermanyEnergy and utilitiesRansomwareNot disclosedNo evidence of data theft
08-09-2026Florida Department of Highway Safety and Motor Vehicles (DAVID database)USAGovernment and public sectorCredential abuseMore than 200,000 (claimed)Confirmed
08-09-2026Greenberg TraurigUSAProfessional servicesData extortionNot disclosed (‘limited’ documents)Confirmed
08-09-2026VeradigmUSAHealthcareData extortion (supply chain)3.5 million (claimed)Confirmed
08-09-2026Vietnam-linked APIS database (operator not identified)VietnamTransport and logisticsMisconfiguration/exposure220,783,700 travel records (not unique people)No evidence of data theft
09-09-2026Brevo (Trezor, BitBox and CoinTracking newsletters)Not statedTechnology and SaaSSupply-chain/third-party347,000 email addresses (Trezor)Confirmed
11-09-2026Japan Digital Agency (Government Solution Service)JapanGovernment and public sectorVulnerability exploitationAbout 246,000 recordsConfirmed
11-09-2026Revolut (fake government requests)UKFinance and insurancePhishing/social engineeringNot disclosed (‘limited’ customers)Confirmed
14-09-2026CenterPoint EnergyUSAEnergy and utilitiesOther/unknown7.49 million (claimed)Confirmed
14-09-2026Unnamed Spanish organisation (AI-agent breach reported to the AEPD)SpainUnknownOther/unknownNot disclosedUnconfirmed
16-09-2026Gyazo (Helpfeel)JapanTechnology and SaaSVulnerability exploitationAbout 23.62 million user recordsConfirmed
18-09-2026BigCommerce merchants via Ribon apps (Fastr / Be A Part Of)USATechnology and SaaSSupply-chain/third-partyNot disclosed (‘hundreds’ of stores)Confirmed
19-09-2026Ludwig Maximilian University of Munich (LMU)GermanyEducationOther/unknownAbout 600,000 data setsConfirmed
21-09-2026DriveWealth (Revolut, Stake and Hatch customers)USAFinance and insurancePhishing/social engineering (supply chain)62,000+ (Rhode Island residents only)Confirmed
22-09-2026Astrana HealthUSAHealthcarePhishing/social engineeringNot disclosedConfirmed
22-09-2026FBI (FBIJobs.gov portal)USAGovernment and public sectorOther/unknown5,000-record sample (claimed)Unconfirmed
23-09-2026Services Australia Medicare statistics portal (OpenAI agent)AustraliaGovernment and public sectorOther/unknownn/a (no personal data reported)No evidence of data theft
24-09-2026BitgetNot statedCrypto and DeFiOther/unknownn/a (about US$387.5m stolen)Confirmed
24-09-2026US Department of Defense – Defense Manpower Data CenterUSAGovernment and public sectorVulnerability exploitation2.76 million living and 294,000 deceased peopleConfirmed
25-09-2026Dyfed-Powys PoliceUKGovernment and public sectorOther/unknownNot disclosed (staff data possibly accessed)Unconfirmed
25-09-2026Simba TelecomSingaporeTelecomsOther/unknown23,549 customersConfirmed
25-09-2026Times Car (Park24 / Times Mobility)JapanTransport and logisticsOther/unknownUp to 6.6 million accountsConfirmed
26-09-2026Keio CorporationJapanTransport and logisticsRansomwareNot disclosedNo evidence of data theft
27-09-2026Tokyo MetroJapanTransport and logisticsOther/unknownAbout 59,000 email addressesConfirmed
29-09-2026Seicomart (Secoma)JapanRetail and consumerOther/unknown572,022 accountsConfirmed
30-09-2026Bee Cheng HiangSingaporeRetail and consumerInsider/human error95,364 email addressesConfirmed
30-09-2026Benefit OneJapanProfessional servicesMisconfiguration/exposure13,460 peopleConfirmed

How we count

We record each incident under the date it first became public, whether that was a company statement, a regulator filing, a credible media report or, once a reputable outlet or regulator reports it, an attacker’s claim.

The confirmed total is a lower bound: it adds only counts verified by the organisation affected, a regulator or independent researcher analysis. The top five ranks incidents by confirmed record counts only; attacker claims are summarised separately. Attacker claims and media estimates are shown but never summed. Incidents we could not verify against two independent sources are left out until we can. The units differ between incidents (accounts, individuals, records) and are summed as reported.

Discover your vulnerabilities before attackers do
To avoid falling victim to cyber attacks, it’s critical to understand where you are most vulnerable to attack. Then you can close any security gaps before it’s too late.

Don’t leave your vulnerabilities to chance. Collaborate with a team that understands your risks and delivers actionable solutions.

Contact our penetration testing experts today to discuss your security needs.