Our research found 40 publicly disclosed data breaches and cyber attacks in September 2026, with at least 252,804,563 records confirmed as breached. That total is a floor: it counts only figures confirmed by the organisation affected, a regulator or an independent researcher, and leaves out a further 164 million records that attackers have claimed. About 87% of the confirmed total comes from one exposed database in Vietnam.

Summary
- Total number of incidents disclosed: 40
- Total number of confirmed records breached (lower bound): 252,804,563, from 18 incidents
The number of breached records comprises those verified by the affected organisation, a regulator or independent researcher analysis.
It excludes the 5 incidents that rest on attacker claims and the 17 incidents with no figure at all, such as cryptocurrency thefts and attacks where the organisation has not said how many people were affected.
The units differ (accounts, individuals, records, email addresses) and are summed as reported. For Gyazo, we count the 23.62 million user records, not the 490 million image-metadata records that were also exposed.
Two large claims that are not in the total
Two attacker claims are large enough that, if verified, both would rank among the month’s five largest incidents. Neither organisation has confirmed the figure, so we have left them out of the confirmed total and the top five below, and summarise them here instead.
IDScan.net
- Records affected: 153 million driver’s licence scans (claimed). IDScan has not said how many people were affected.
- Data: Names, driver’s licence numbers and other government ID numbers; the marketplace listing also offers licence images and other ID documents.
- Cause: Not disclosed. IDScan says an unauthorised third party accessed customer information in its cloud platform; a journalist traced authenticated samples to the company.
- Status: Breach confirmed by the company in a notice dated 4 September. The record count is unconfirmed.
CenterPoint Energy
- Records affected: 7.49 million customer records (claimed). CenterPoint has not confirmed a count.
- Data: Claimed: names, phone numbers, email addresses, service and billing addresses, account and premise IDs, billing amounts and the last four digits of Social Security numbers. CenterPoint has confirmed only that personal information was taken.
- Cause: CenterPoint says a third party obtained data through an external-facing system. The person who leaked the data says it was an API with no authentication or rate limiting; the company has not confirmed that.
- Status: Breach confirmed in a Form 8-K filed on 14 September. The scope is under investigation.
Top five incidents by confirmed records affected
The five largest incidents publicly disclosed in September 2026, ranked by confirmed number of records (attacker claims are covered separately above):

1. Vietnam-linked APIS database
- Records affected: 220,783,700 travel records, not unique people (confirmed by independent researchers).
- Data: Names, dates of birth, sex, nationality, passport or travel-document numbers and expiry dates, plus flight, seat and baggage details for people who travelled to, from or through Vietnam between 2017 and 2026.
- Cause: An Elasticsearch database named ‘pax-info’ was reachable through two chained misconfigurations: a cloud path and default credentials.
- Status: Confirmed exposure. Kinryū Labs found it on 3 June and it was secured on 8 June. There is no evidence that anyone copied the data, and the operator has not been identified.
2. Gyazo (Helpfeel)
- Records affected: 23.62 million user records (confirmed). A further 490 million image-metadata records were also exposed and are not counted.
- Data: Names or nicknames, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google single sign-on email addresses, and subscription and billing status. Payment data was not exposed.
- Cause: An attacker exploited a vulnerability in Gyazo’s image-upload server on 11 September and ran commands on it.
- Status: Confirmed by Helpfeel, Gyazo’s operator, on 16 September. No attacker has been named.
3. US Department of Defense (Defense Manpower Data Center)
- Records affected: 3,054,000 people: 2.76 million living and 294,000 deceased (confirmed by the Department of Defense).
- Data: Social Security numbers, occupational specialties and other military and civilian personnel details, all unencrypted.
- Cause: A vulnerability in a Defense Manpower Data Center file-sharing system. Unauthorised users had access from October 2025 until the centre found and patched the flaw on 16 July 2026.
- Status: Confirmed. Military Times reported the breach on 24 September, and defence officials confirmed the counts to CNN and ABC on 28 September; the notification letter is dated 18 September. The centre has not said who was responsible. Some outlets suggest up to 4 million people could be affected, but that figure is unverified.
4. Times Car (Park24)
- Records affected: About 1.6 million accounts with identity documents confirmed leaked. The company’s stated maximum is 6.6 million accounts.
- Data: Names, addresses, dates of birth, phone numbers, email addresses, driving licence details and identity documents. Passwords were stored in a non-restorable form and no card data was taken.
- Cause: Unauthorised access to the Times Car web system, detected on 25 September. The company has not said how the attacker got in.
- Status: Confirmed by Park24, the parent company, on 25 September. The investigation is continuing and the incident has been reported to Japan’s data protection regulator.
5. Mathspace
- Records affected: 1,079,819 people: students, staff and parents or guardians in Australia and New Zealand (confirmed by Mathspace).
- Data: User IDs, usernames, names, email addresses, country, time zone, user type, email-verification status, and last-active and login dates. No passwords, academic data or authentication tokens were exposed.
- Cause: An unpatched vulnerability in Metabase, the self-hosted reporting software Mathspace uses. Metabase patched the flaw on 6 August; Mathspace’s process failed to escalate the advisory and it updated on 29 August. Attackers had access from 10 August and downloaded data on 27 August.
- Status: Confirmed by Mathspace, which verified the breach on 3 September after reviewing access logs and began notifying schools on 4 September. No attacker has been named.
Trends in September 2026
This is our first monthly report since October 2025, so we’re making no month-on-month comparisons this time. However, several patterns stand out:
- Claimed figures came to about 164 million records
Five incidents rest on claimed figures, together about 164 million records: IDScan (153 million), CenterPoint (7.49 million), Veradigm (3.5 million), the Florida driver database (200,000) and the FBI jobs portal (a 5,000-record sample). Only 18 of the 40 incidents have a confirmed count.

- Third parties were the way in for six incidents
IDScan, DriveWealth, BigCommerce through its Ribon apps, Veradigm, Brevo and Dropbox through Lenovo ID all involved a supplier or partner rather than the victim’s own systems. Another 7 incidents involved exploited vulnerabilities and the cause of 14 is still not public.

- Japan accounted for half of the Asia-Pacific total
Asia-Pacific had 14 incidents, level with North America. Seven involved Japanese organisations (Gyazo, Times Car, the Digital Agency, Keio, Tokyo Metro, Seicomart and Benefit One), and five of those were disclosed between 25 and 30 September.

- AI tools appeared in three incident reports
An OpenAI research agent reached non-public files on an Australian Medicare statistics portal; a Spanish organisation told its regulator that an AI agent ran an attack on its systems; and a Singapore retailer’s AI-written mailing script exposed 95,364 customers’ email addresses. Spain’s data protection agency and Singapore’s regulator each called theirs the first notification of its kind. - Cryptocurrency thefts have no record counts
Bitget lost about US$387.5 million (revised up from US$351.6 million) and the Liquid Network about US$320 million, of which about US$47 million was not returned. We list both in the table but do not rank them.

Key vulnerabilities exploited
- Unpatched software
Mathspace’s self-hosted Metabase instance had a vulnerability disclosed on 6 August that went unactioned until 29 August; Japan’s Digital Agency was hit through a VPN flaw that had a patch available; the Pentagon’s Defense Manpower Data Center had a file-sharing system vulnerability that exposed unencrypted records for about nine months. - Zero-days
Bimbo Bakeries says an Oracle E-Business Suite zero-day exposed files containing names and Social Security numbers; ShinyHunters claims a PeopleSoft zero-day gave it access to the FBI jobs portal, which the FBI has not confirmed (Mandiant reports renewed exploitation of CVE-2026-35273 in PeopleSoft); the Liquid Network lost funds to a bug in how Elements caches range-proof verifications. - Third-party credentials and keys
A compromised application key held by the Ribon apps exposed BigCommerce shopper data; stolen vendor credentials reached a Veradigm API; a single sign-on flaw let an attacker into 138 Brevo accounts; and a Lenovo email-verification flaw let attackers into about 5,000 Dropbox accounts. - Stored, default and misconfigured credentials
Florida’s DAVID database was reached with a police user’s credentials kept on a personal device; the Vietnamese passenger database accepted default credentials; Benefit One’s survey function showed other organisations’ employee data because of a configuration error. - Social engineering and impersonation
Revolut released customer data to someone using a government agency’s email domain; DriveWealth, Astrana and Quinn Emanuel were each reached through social engineering, in Astrana’s case with a spoofed company phone number.
List of data breaches and cyber attacks disclosed in September 2026
| Disclosure date | Organisation | Country | Sector | Incident type | Records affected | Status |
| 01-09-2026 | IDScan.net | USA | Technology and SaaS | Supply-chain/third-party | 153 million licence scans (claimed) | Confirmed |
| 01-09-2026 | Novocure | USA | Healthcare | Data extortion | More than 1,400 patient records | Confirmed |
| 02-09-2026 | Dropbox (via Lenovo ID) | USA | Technology and SaaS | Supply-chain/third-party | About 5,000 accounts | Confirmed |
| 03-09-2026 | P&O Ferries | UK | Transport and logistics | Insider/human error | Not disclosed (one sailing) | Confirmed |
| 03-09-2026 | Quinn Emanuel Urquhart & Sullivan | USA | Professional services | Phishing/social engineering | Not disclosed | Confirmed |
| 04-09-2026 | Bimbo Bakeries USA | USA | Manufacturing | Vulnerability exploitation | Not disclosed | Confirmed |
| 04-09-2026 | Natural Resources Wales | UK | Government and public sector | Insider/human error | Not disclosed (staff employed 2013–2018) | Confirmed |
| 06-09-2026 | Liquid Network (Blockstream) | Not stated | Crypto and DeFi | Vulnerability exploitation | n/a (about US$320m taken; about US$47m kept) | Confirmed |
| 06-09-2026 | Mathspace | Australia | Education | Vulnerability exploitation | 1,079,819 people | Confirmed |
| 06-09-2026 | Weverse (HYBE) | South Korea | Media and entertainment | Vulnerability exploitation | 422,584 accounts | Confirmed |
| 07-09-2026 | City of Everett, Massachusetts | USA | Government and public sector | Other/unknown | Not disclosed | No evidence of data theft |
| 07-09-2026 | Gangnam Unni (Healing Paper) | South Korea | Healthcare | Other/unknown | 219,665 users | Confirmed |
| 07-09-2026 | Springfield Public Schools (Massachusetts) | USA | Education | Other/unknown | Not disclosed | No evidence of data theft |
| 07-09-2026 | Stadtwerke Landsberg | Germany | Energy and utilities | Ransomware | Not disclosed | No evidence of data theft |
| 08-09-2026 | Florida Department of Highway Safety and Motor Vehicles (DAVID database) | USA | Government and public sector | Credential abuse | More than 200,000 (claimed) | Confirmed |
| 08-09-2026 | Greenberg Traurig | USA | Professional services | Data extortion | Not disclosed (‘limited’ documents) | Confirmed |
| 08-09-2026 | Veradigm | USA | Healthcare | Data extortion (supply chain) | 3.5 million (claimed) | Confirmed |
| 08-09-2026 | Vietnam-linked APIS database (operator not identified) | Vietnam | Transport and logistics | Misconfiguration/exposure | 220,783,700 travel records (not unique people) | No evidence of data theft |
| 09-09-2026 | Brevo (Trezor, BitBox and CoinTracking newsletters) | Not stated | Technology and SaaS | Supply-chain/third-party | 347,000 email addresses (Trezor) | Confirmed |
| 11-09-2026 | Japan Digital Agency (Government Solution Service) | Japan | Government and public sector | Vulnerability exploitation | About 246,000 records | Confirmed |
| 11-09-2026 | Revolut (fake government requests) | UK | Finance and insurance | Phishing/social engineering | Not disclosed (‘limited’ customers) | Confirmed |
| 14-09-2026 | CenterPoint Energy | USA | Energy and utilities | Other/unknown | 7.49 million (claimed) | Confirmed |
| 14-09-2026 | Unnamed Spanish organisation (AI-agent breach reported to the AEPD) | Spain | Unknown | Other/unknown | Not disclosed | Unconfirmed |
| 16-09-2026 | Gyazo (Helpfeel) | Japan | Technology and SaaS | Vulnerability exploitation | About 23.62 million user records | Confirmed |
| 18-09-2026 | BigCommerce merchants via Ribon apps (Fastr / Be A Part Of) | USA | Technology and SaaS | Supply-chain/third-party | Not disclosed (‘hundreds’ of stores) | Confirmed |
| 19-09-2026 | Ludwig Maximilian University of Munich (LMU) | Germany | Education | Other/unknown | About 600,000 data sets | Confirmed |
| 21-09-2026 | DriveWealth (Revolut, Stake and Hatch customers) | USA | Finance and insurance | Phishing/social engineering (supply chain) | 62,000+ (Rhode Island residents only) | Confirmed |
| 22-09-2026 | Astrana Health | USA | Healthcare | Phishing/social engineering | Not disclosed | Confirmed |
| 22-09-2026 | FBI (FBIJobs.gov portal) | USA | Government and public sector | Other/unknown | 5,000-record sample (claimed) | Unconfirmed |
| 23-09-2026 | Services Australia Medicare statistics portal (OpenAI agent) | Australia | Government and public sector | Other/unknown | n/a (no personal data reported) | No evidence of data theft |
| 24-09-2026 | Bitget | Not stated | Crypto and DeFi | Other/unknown | n/a (about US$387.5m stolen) | Confirmed |
| 24-09-2026 | US Department of Defense – Defense Manpower Data Center | USA | Government and public sector | Vulnerability exploitation | 2.76 million living and 294,000 deceased people | Confirmed |
| 25-09-2026 | Dyfed-Powys Police | UK | Government and public sector | Other/unknown | Not disclosed (staff data possibly accessed) | Unconfirmed |
| 25-09-2026 | Simba Telecom | Singapore | Telecoms | Other/unknown | 23,549 customers | Confirmed |
| 25-09-2026 | Times Car (Park24 / Times Mobility) | Japan | Transport and logistics | Other/unknown | Up to 6.6 million accounts | Confirmed |
| 26-09-2026 | Keio Corporation | Japan | Transport and logistics | Ransomware | Not disclosed | No evidence of data theft |
| 27-09-2026 | Tokyo Metro | Japan | Transport and logistics | Other/unknown | About 59,000 email addresses | Confirmed |
| 29-09-2026 | Seicomart (Secoma) | Japan | Retail and consumer | Other/unknown | 572,022 accounts | Confirmed |
| 30-09-2026 | Bee Cheng Hiang | Singapore | Retail and consumer | Insider/human error | 95,364 email addresses | Confirmed |
| 30-09-2026 | Benefit One | Japan | Professional services | Misconfiguration/exposure | 13,460 people | Confirmed |
How we count
We record each incident under the date it first became public, whether that was a company statement, a regulator filing, a credible media report or, once a reputable outlet or regulator reports it, an attacker’s claim.
The confirmed total is a lower bound: it adds only counts verified by the organisation affected, a regulator or independent researcher analysis. The top five ranks incidents by confirmed record counts only; attacker claims are summarised separately. Attacker claims and media estimates are shown but never summed. Incidents we could not verify against two independent sources are left out until we can. The units differ between incidents (accounts, individuals, records) and are summed as reported.