Back to Blog

Biggest data breaches of September 2026

Shubham JhaOctober 6, 202618 min read
TL;DR
  • ✓IDScan.net carries the month's biggest number. A seller claims 153 million driver's license scans, and IDScan confirms an intruder was in its VeriScan cloud from April 4 to September 2, though it hasn't said how many people are affected.
  • ✓The largest company-confirmed counts belong to Gyazo, with about 23.62 million user records, and Times Car, with up to about 6.6 million accounts, about 1.6 million of them with identity documents attached.
  • ✓Four headline numbers come only from attackers or sellers: IDScan's 153 million, CenterPoint Energy's 7.49 million, Florida DMV's 200,000 and the FBI's 2 to 3TB.
  • ✓The common thread is access already handed out (a police login, a third-party app key), controls assumed to work (a WAF rule and an unthrottled API, both per attackers) and data kept long after it was needed.
  • ✓Every figure below is tied to a company statement, a regulatory filing or a named security outlet. Attacker claims are labeled as claims.

September's biggest breach numbers came with an asterisk. In four of the eight incidents below, the headline figure comes from the attacker or the seller, and the company hasn't confirmed it. So we've labeled every number by where it came from. Every incident here first became public in September 2026, and most also happened that month.

What were the biggest data breaches of September 2026?

# Organization Scale Entry point Threat actor Confidence
1 IDScan.net 153M+ licenses claimed Cloud platform access, Apr 4 to Sep 2 Unknown Access confirmed by company; scale seller-claimed
2 Gyazo ~23.62M user records Upload server vulnerability Unknown Confirmed by company
3 CenterPoint Energy 7.49M records claimed External-facing system (attacker says an open API) "4d722e4d656f77" (claimed) Access confirmed in SEC 8-K; scale attacker-claimed
4 Times Car Up to ~6.6M accounts (~1.6M with ID documents) Unauthorized web system access Unknown Confirmed by company; final count pending
5 FBI (FBIJobs.gov) 2 to 3TB claimed PeopleSoft WAF bypass (per attacker) ShinyHunters (claimed) FBI investigating; breach and theft unconfirmed
6 Florida DMV (DAVID) 200,000+ records claimed Police employee's login stored on a personal device (per agency) ShinyHunters (claimed) Breach confirmed by agency; scale attacker-claimed
7 DriveWealth No total; ~62,000 Rhode Island residents in state notices Social engineering campaign (per company) Unknown Confirmed by company
8 BigCommerce stores via Ribon Not disclosed; app installed on "hundreds" of stores Compromised third-party app key Unknown Confirmed by BigCommerce and Master of Malt

What happened in each breach?

1. IDScan.net: 153 million licenses for sale, five months inside the cloud

Access April 4 to September 2 · Reported September 1, 2026 · Identity verification · United States · Actor unknown

On August 31, a source pointed Brian Krebs to a new service called Nexus on the Russian cybercrime forum Exploit. It claimed to sell scans of more than 153 million US and Canadian driver's licenses, plus more than 10 million ID cards, more than three million travel documents and at least 579,000 medical cards. With permission, Krebs searched for the licenses of more than a dozen friends and family members, traced the images to Louisiana-based IDScan.net, and reported on September 1 that the FBI's New Orleans field office had opened an investigation. Nexus went offline soon after.

IDScan's notice, posted September 4 and updated September 29, says an unauthorized third party had access to "a portion of our cloud environment" between April 4 and September 2, limited to its VeriScan platform. Depending on what each business customer collected, the data can include names, contact details, dates of birth, and driver's license, passport or other government ID numbers. IDScan hasn't published a victim count or said how the attacker got in, and it's offering free credit monitoring. Canada's Privacy Commissioner opened a formal investigation on September 21.

One gap is still open. Nexus claimed it had been "continuously exfiltrating new data for over a year," which is far longer than the five months IDScan has confirmed.

2. Gyazo: 23.6 million user records, and metadata for images users had deleted

Attack September 11 · Disclosed September 16, updated September 25, 2026 · SaaS / image sharing · Japan · Actor unknown

Helpfeel, the Kyoto-based company behind the screenshot tool, says an attacker exploited a vulnerability in Gyazo's image upload server on September 11, ran arbitrary commands and reached its database. Helpfeel spotted the activity that evening and cut off access by the next morning. Its September 16 notice confirmed about 23.62 million user records and about 490 million image metadata records were exposed. User records include names or nicknames, email addresses, password hashes, device and session IDs, and X integration tokens. The image metadata, mostly for images uploaded in or before January 2019, includes upload IP addresses, EXIF location data, text pulled from images by OCR and the image IDs used to build image URLs. That last field is why Helpfeel paused image viewing. No payment data was exposed.

The September 25 update added two details. About 18.01 million of the user records, roughly 76%, belong to anonymous accounts with no email address. And metadata for about 174 million images that users had already deleted, mostly in or before February 2023, was exposed too, though the deleted image files themselves weren't. Helpfeel hasn't named the vulnerability or the attacker.

Those users hit delete years ago. The records describing their images stayed on the server, and they left with everything else.

3. CenterPoint Energy: a confirmed breach where only the attacker has given numbers

Claim posted early September · 8-K filed September 14, 2026 · Energy / utilities · United States · "4d722e4d656f77" (claimed)

In a Form 8-K filed September 14, the Houston-based utility said it learned in September of an online post from a third party claiming to hold its customer data. It confirmed that personal information for a portion of its customers was obtained "through one of the Company's external facing systems." Electric and gas service wasn't affected. CenterPoint hasn't said how many customers were involved, what data was taken or when. When Fox News asked for more, the company said: "Our filing speaks for itself."

The attacker, using the alias "4d722e4d656f77," told BleepingComputer it took 7.49 million customer records with names, phone numbers, service and billing addresses, account numbers, billing amounts and partial Social Security numbers. It says it cycled through IDs on a public API that had no rate limiting or WAF protection, and it has since leaked the data. CenterPoint hasn't confirmed any of that. Class action lawsuits filed by customers allege the breach ran from August 17 to September 1.

4. Times Car: up to 6.6 million accounts, 1.6 million with ID documents

Detected September 25 · Contained September 26 · Scope confirmed September 28, 2026 · Car sharing · Japan · Actor unknown

Times Mobility, the Park24 Group company that runs Japan's Times Car car-sharing service, detected unauthorized access to its web systems at 9:07 a.m. on September 25 and says it cut off the attacker by September 26. On September 28 it confirmed that data from about 6.6 million current and former accounts had been taken, a figure that includes members of its Times Business Service corporate program. Park24 has since told MLex that 6.6 million is the maximum number of potentially affected accounts and that the final count is still under investigation.

Exposed data varies by account and includes names, addresses, dates of birth, phone numbers, email addresses, driver's license details and account passwords, which Times Car says were stored in a form that can't be restored. A September 29 update confirmed that identity verification documents tied to about 1.6 million accounts were accessed: driver's license images, utility bills used to prove address, student ID cards for student-plan users and family verification documents. Card data wasn't affected. Times Car has reported the breach to the authorities and the police, the entry point is still under investigation, and there's no evidence yet that the data has been published or misused.

5. FBI: ShinyHunters claims FBIJobs.gov and points to a PeopleSoft flaw Oracle patched in June

Claim made September 22 · Google research September 25, 2026 · Government / law enforcement · United States · ShinyHunters (claimed)

On September 22, ShinyHunters defaced a page on FBIJobs.gov and claimed it had stolen data on FBI agents and job applicants. The group told BleepingComputer it got in through a new Oracle PeopleSoft zero-day and moved into the FBI's AWS GovCloud environment, and it told 404 Media it took 2 to 3TB of data. 404 Media received a sample covering about 5,000 purported agents. The FBI says it's investigating, and in a later post on X it said the point of breach was still undetermined, whether a third party or the FBI's own enterprise. It hasn't confirmed that any data was stolen.

Three days later, Google Threat Intelligence and Mandiant reported renewed mass exploitation of CVE-2026-35273, a CVSS 9.8 unauthenticated remote code execution flaw in PeopleSoft's Environment Management Hub (PSEMHUB). UNC6240, the cluster Google tracks as ShinyHunters, first exploited it as a zero-day starting May 27, before Oracle shipped an emergency fix on June 10. The new wave goes after organizations that blocked the endpoint with a WAF rule and never patched. Requesting /%50SEMHUB/ instead of /PSEMHUB/ slips past rules that match the literal path, and the PeopleSoft server decodes it straight back to the vulnerable servlet. Google's research doesn't name the FBI as a victim. ShinyHunters later told BleepingComputer it used that same WAF bypass against FBI Jobs, while still claiming it also exploited a second, unknown PSEMHUB flaw.

Oracle shipped the fix in June. Anyone who put a WAF rule in front of the flaw instead was one encoded character away from this attack.

6. Florida DMV (DAVID): one police employee's saved login

Access claimed from September 3 · Agency learned September 4 · Claim reported September 8, 2026 · State government · United States · ShinyHunters (claimed)

ShinyHunters listed the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) on its leak site and claimed it had breached DAVID, the Driver and Vehicle Information Database that police and officials use to look up driver and vehicle records. It claimed more than 200,000 records pulled from September 3, and told BleepingComputer it got in through a password-reset flaw that let it take over several accounts, allegedly including DMV employees and an FBI agent. As proof, it posted Jeffrey Epstein's DAVID record.

In a September 11 statement, FLHSMV confirmed it learned of the breach on September 4 and contained it quickly. Its account of the entry point is different: a criminal group used the credentials of a single Plant City Police Department user, which were improperly stored on that employee's personal device. The agency hasn't confirmed the 200,000 figure. By September 16, ShinyHunters had published hundreds of thousands of files, saying the state hadn't paid. In the copy TechCrunch reviewed, most were vehicle ownership records with buyer and seller names, addresses and VINs, and a smaller share included Social Security numbers, non-US passports and immigration papers. TechCrunch didn't find driver's licenses or photos, though Hackread's own analysis of the leak reported Social Security cards and licenses among the files.

A database built for police lookups was opened with a police department login, kept on a device it should never have been on.

7. DriveWealth: two days of access reached years-old Revolut records

Access September 4 to 5 · Customer notices from September 21, 2026 · Financial services / brokerage · United States · Actor unknown

DriveWealth, the US broker behind stock trading in apps such as Revolut, Stake and Hatch, says unknown attackers got into its network on September 4 and 5 through a social engineering campaign, and that it contained the compromise on September 5. Its notice to state regulators says the review finished on September 28 and confirmed that names and other personal information were taken. No passwords, card details or bank account details were involved, and DriveWealth found no unauthorized trades, transfers or withdrawals.

The exposed data may include names, contact details, postal addresses, employment details, country of citizenship, age, gender and partial account numbers. For Stake and Hatch users, it also included portfolio values and cash balances. DriveWealth hasn't given a total, but its notices list about 62,000 affected Rhode Island residents. Revolut says its European customers' records date from before December 2023, when it moved them off the DriveWealth arrangement, and that DriveWealth kept the data to meet regulatory obligations. It's the second incident to hit Revolut customers this month. On September 12, Revolut confirmed it had released customer data to scammers posing as government officials.

8. BigCommerce stores via Ribon: one third-party app key, one evening of downloads

Key misused September 13 · Revoked September 17 · Merchants notified from September 18, 2026 · E-commerce · United States / United Kingdom · Actor unknown

BigCommerce says it confirmed on September 17 that API credentials for the third-party apps Ribon and Ribon 1.5, run by Be A Part Of (a Fastr company), had been compromised through a breach at Fastr and used to inject malicious scripts into a small number of merchant storefronts. It removed the apps from affected stores, started notifying merchants on September 18, and says its own platform wasn't breached.

UK spirits retailer Master of Malt has published the most detailed account. On the evening of September 13, someone used Ribon's stolen key to download customer names, email addresses, phone numbers and postal addresses, page by page. The app's developer learned of the misuse on September 16, and the key was switched off on September 17. Passwords and payment details sit in a separate system that wasn't touched. Ribon was installed on hundreds of BigCommerce stores, Master of Malt says, but that's an install count, and nobody has said how many stores or shoppers were actually hit. Master of Malt has reported the incident to the UK Information Commissioner's Office.

What do September's breaches have in common?

Few of them needed a clever new exploit. Most came down to something the organization had stopped watching.

Start with access that was already handed out. Florida's attacker logged in with a real police account. The BigCommerce attacker used a real app key, and Master of Malt points out that only the app's developer or BigCommerce could have seen it being misused. DriveWealth's attackers talked their way in.

Then there are controls that were assumed to work. If the attackers' accounts are accurate, FBI Jobs sat behind a WAF rule that one encoded character defeats, and CenterPoint's customer API had no rate limiting to stop someone walking through millions of IDs.

And then there's data kept long after it was needed. Gyazo still held metadata for images deleted years ago. DriveWealth still held Revolut records from accounts that moved in 2023. IDScan and Times Car both stored images of government IDs, and attackers reached them.

What should security teams do now?

  • If you run PeopleSoft, apply Oracle's June 10 fix for CVE-2026-35273 and stop relying on a WAF rule. Search your logs for requests to /%50SEMHUB/, and rotate any credentials the PeopleSoft service account can read.

  • List every third-party app key on your commerce and SaaS platforms, cut each one's scope to what the app actually uses, and alert on bulk customer downloads.

  • Keep logins that can query sensitive records off personal devices, and put phishing-resistant MFA on them.

  • Rate-limit and monitor any public API that returns customer data by ID.

  • Set retention limits for identity documents and deleted content. Then check that "deleted" also removes the metadata.

A WAF rule or a "temporary" mitigation is an assumption until someone tries to get past it, and attackers will try encodings your rule never considered. That's the gap continuous testing closes. Strobes exposure validation runs those attempts against your own perimeter and APIs on a schedule, so you learn a compensating control has a hole before ShinyHunters does. Agentic pentesting covers the slower questions, like whether an endpoint leaks records when you iterate IDs, or what a single compromised account or app key can actually reach. It won't stop a phished employee, but it tells you how far one could get.

For earlier months, see the biggest data breaches of August 2026 and our month-by-month breach archive. For the vulnerabilities behind many of these incidents, read the latest top CVEs roundup.

FAQ

What was the biggest data breach of September 2026?

By claimed size, IDScan.net, where a seller says it has more than 153 million driver's license scans. IDScan has confirmed the breach but not the number. By company-confirmed count, Gyazo is the largest, with about 23.62 million user records and about 490 million image metadata records.

Did ShinyHunters really breach the FBI?

It's unconfirmed. The FBI says it's investigating unauthorized activity affecting FBIJobs.gov and hasn't determined the point of breach or confirmed data theft. The 2 to 3TB figure comes only from ShinyHunters.

What is CVE-2026-35273?

It's a CVSS 9.8 unauthenticated remote code execution flaw in Oracle PeopleSoft's Environment Management Hub. ShinyHunters exploited it as a zero-day from late May, Oracle patched it on June 10, and Google reported in September that the group is now bypassing WAF rules on systems that were never patched.

Were Revolut's own systems breached?

Not in the DriveWealth incident. The data was taken from DriveWealth's network, and Revolut says its own systems, passwords, card details and ID documents weren't affected. Revolut separately confirmed on September 12 that it had released some customer data to scammers posing as government officials.

Sources

1. IDScan.net

2. Gyazo

3. CenterPoint Energy

4. Times Car

5. FBI (FBIJobs.gov)

6. Florida DMV (DAVID)

7. DriveWealth

8. BigCommerce stores via Ribon