Biggest data breaches of September 2026
- ✓IDScan.net carries the month's biggest number. A seller claims 153 million driver's license scans, and IDScan confirms an intruder was in its VeriScan cloud from April 4 to September 2, though it hasn't said how many people are affected.
- ✓The largest company-confirmed counts belong to Gyazo, with about 23.62 million user records, and Times Car, with up to about 6.6 million accounts, about 1.6 million of them with identity documents attached.
- ✓Four headline numbers come only from attackers or sellers: IDScan's 153 million, CenterPoint Energy's 7.49 million, Florida DMV's 200,000 and the FBI's 2 to 3TB.
- ✓The common thread is access already handed out (a police login, a third-party app key), controls assumed to work (a WAF rule and an unthrottled API, both per attackers) and data kept long after it was needed.
- ✓Every figure below is tied to a company statement, a regulatory filing or a named security outlet. Attacker claims are labeled as claims.
September's biggest breach numbers came with an asterisk. In four of the eight incidents below, the headline figure comes from the attacker or the seller, and the company hasn't confirmed it. So we've labeled every number by where it came from. Every incident here first became public in September 2026, and most also happened that month.
What were the biggest data breaches of September 2026?
| # | Organization | Scale | Entry point | Threat actor | Confidence |
|---|---|---|---|---|---|
| 1 | IDScan.net | 153M+ licenses claimed | Cloud platform access, Apr 4 to Sep 2 | Unknown | Access confirmed by company; scale seller-claimed |
| 2 | Gyazo | ~23.62M user records | Upload server vulnerability | Unknown | Confirmed by company |
| 3 | CenterPoint Energy | 7.49M records claimed | External-facing system (attacker says an open API) | "4d722e4d656f77" (claimed) | Access confirmed in SEC 8-K; scale attacker-claimed |
| 4 | Times Car | Up to ~6.6M accounts (~1.6M with ID documents) | Unauthorized web system access | Unknown | Confirmed by company; final count pending |
| 5 | FBI (FBIJobs.gov) | 2 to 3TB claimed | PeopleSoft WAF bypass (per attacker) | ShinyHunters (claimed) | FBI investigating; breach and theft unconfirmed |
| 6 | Florida DMV (DAVID) | 200,000+ records claimed | Police employee's login stored on a personal device (per agency) | ShinyHunters (claimed) | Breach confirmed by agency; scale attacker-claimed |
| 7 | DriveWealth | No total; ~62,000 Rhode Island residents in state notices | Social engineering campaign (per company) | Unknown | Confirmed by company |
| 8 | BigCommerce stores via Ribon | Not disclosed; app installed on "hundreds" of stores | Compromised third-party app key | Unknown | Confirmed by BigCommerce and Master of Malt |
What happened in each breach?
1. IDScan.net: 153 million licenses for sale, five months inside the cloud
Access April 4 to September 2 · Reported September 1, 2026 · Identity verification · United States · Actor unknown
On August 31, a source pointed Brian Krebs to a new service called Nexus on the Russian cybercrime forum Exploit. It claimed to sell scans of more than 153 million US and Canadian driver's licenses, plus more than 10 million ID cards, more than three million travel documents and at least 579,000 medical cards. With permission, Krebs searched for the licenses of more than a dozen friends and family members, traced the images to Louisiana-based IDScan.net, and reported on September 1 that the FBI's New Orleans field office had opened an investigation. Nexus went offline soon after.
IDScan's notice, posted September 4 and updated September 29, says an unauthorized third party had access to "a portion of our cloud environment" between April 4 and September 2, limited to its VeriScan platform. Depending on what each business customer collected, the data can include names, contact details, dates of birth, and driver's license, passport or other government ID numbers. IDScan hasn't published a victim count or said how the attacker got in, and it's offering free credit monitoring. Canada's Privacy Commissioner opened a formal investigation on September 21.
One gap is still open. Nexus claimed it had been "continuously exfiltrating new data for over a year," which is far longer than the five months IDScan has confirmed.
2. Gyazo: 23.6 million user records, and metadata for images users had deleted
Attack September 11 · Disclosed September 16, updated September 25, 2026 · SaaS / image sharing · Japan · Actor unknown
Helpfeel, the Kyoto-based company behind the screenshot tool, says an attacker exploited a vulnerability in Gyazo's image upload server on September 11, ran arbitrary commands and reached its database. Helpfeel spotted the activity that evening and cut off access by the next morning. Its September 16 notice confirmed about 23.62 million user records and about 490 million image metadata records were exposed. User records include names or nicknames, email addresses, password hashes, device and session IDs, and X integration tokens. The image metadata, mostly for images uploaded in or before January 2019, includes upload IP addresses, EXIF location data, text pulled from images by OCR and the image IDs used to build image URLs. That last field is why Helpfeel paused image viewing. No payment data was exposed.
The September 25 update added two details. About 18.01 million of the user records, roughly 76%, belong to anonymous accounts with no email address. And metadata for about 174 million images that users had already deleted, mostly in or before February 2023, was exposed too, though the deleted image files themselves weren't. Helpfeel hasn't named the vulnerability or the attacker.
Those users hit delete years ago. The records describing their images stayed on the server, and they left with everything else.
3. CenterPoint Energy: a confirmed breach where only the attacker has given numbers
Claim posted early September · 8-K filed September 14, 2026 · Energy / utilities · United States · "4d722e4d656f77" (claimed)
In a Form 8-K filed September 14, the Houston-based utility said it learned in September of an online post from a third party claiming to hold its customer data. It confirmed that personal information for a portion of its customers was obtained "through one of the Company's external facing systems." Electric and gas service wasn't affected. CenterPoint hasn't said how many customers were involved, what data was taken or when. When Fox News asked for more, the company said: "Our filing speaks for itself."
The attacker, using the alias "4d722e4d656f77," told BleepingComputer it took 7.49 million customer records with names, phone numbers, service and billing addresses, account numbers, billing amounts and partial Social Security numbers. It says it cycled through IDs on a public API that had no rate limiting or WAF protection, and it has since leaked the data. CenterPoint hasn't confirmed any of that. Class action lawsuits filed by customers allege the breach ran from August 17 to September 1.
4. Times Car: up to 6.6 million accounts, 1.6 million with ID documents
Detected September 25 · Contained September 26 · Scope confirmed September 28, 2026 · Car sharing · Japan · Actor unknown
Times Mobility, the Park24 Group company that runs Japan's Times Car car-sharing service, detected unauthorized access to its web systems at 9:07 a.m. on September 25 and says it cut off the attacker by September 26. On September 28 it confirmed that data from about 6.6 million current and former accounts had been taken, a figure that includes members of its Times Business Service corporate program. Park24 has since told MLex that 6.6 million is the maximum number of potentially affected accounts and that the final count is still under investigation.
Exposed data varies by account and includes names, addresses, dates of birth, phone numbers, email addresses, driver's license details and account passwords, which Times Car says were stored in a form that can't be restored. A September 29 update confirmed that identity verification documents tied to about 1.6 million accounts were accessed: driver's license images, utility bills used to prove address, student ID cards for student-plan users and family verification documents. Card data wasn't affected. Times Car has reported the breach to the authorities and the police, the entry point is still under investigation, and there's no evidence yet that the data has been published or misused.
5. FBI: ShinyHunters claims FBIJobs.gov and points to a PeopleSoft flaw Oracle patched in June
Claim made September 22 · Google research September 25, 2026 · Government / law enforcement · United States · ShinyHunters (claimed)
On September 22, ShinyHunters defaced a page on FBIJobs.gov and claimed it had stolen data on FBI agents and job applicants. The group told BleepingComputer it got in through a new Oracle PeopleSoft zero-day and moved into the FBI's AWS GovCloud environment, and it told 404 Media it took 2 to 3TB of data. 404 Media received a sample covering about 5,000 purported agents. The FBI says it's investigating, and in a later post on X it said the point of breach was still undetermined, whether a third party or the FBI's own enterprise. It hasn't confirmed that any data was stolen.
Three days later, Google Threat Intelligence and Mandiant reported renewed mass exploitation of CVE-2026-35273, a CVSS 9.8 unauthenticated remote code execution flaw in PeopleSoft's Environment Management Hub (PSEMHUB). UNC6240, the cluster Google tracks as ShinyHunters, first exploited it as a zero-day starting May 27, before Oracle shipped an emergency fix on June 10. The new wave goes after organizations that blocked the endpoint with a WAF rule and never patched. Requesting /%50SEMHUB/ instead of /PSEMHUB/ slips past rules that match the literal path, and the PeopleSoft server decodes it straight back to the vulnerable servlet. Google's research doesn't name the FBI as a victim. ShinyHunters later told BleepingComputer it used that same WAF bypass against FBI Jobs, while still claiming it also exploited a second, unknown PSEMHUB flaw.
Oracle shipped the fix in June. Anyone who put a WAF rule in front of the flaw instead was one encoded character away from this attack.
6. Florida DMV (DAVID): one police employee's saved login
Access claimed from September 3 · Agency learned September 4 · Claim reported September 8, 2026 · State government · United States · ShinyHunters (claimed)
ShinyHunters listed the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) on its leak site and claimed it had breached DAVID, the Driver and Vehicle Information Database that police and officials use to look up driver and vehicle records. It claimed more than 200,000 records pulled from September 3, and told BleepingComputer it got in through a password-reset flaw that let it take over several accounts, allegedly including DMV employees and an FBI agent. As proof, it posted Jeffrey Epstein's DAVID record.
In a September 11 statement, FLHSMV confirmed it learned of the breach on September 4 and contained it quickly. Its account of the entry point is different: a criminal group used the credentials of a single Plant City Police Department user, which were improperly stored on that employee's personal device. The agency hasn't confirmed the 200,000 figure. By September 16, ShinyHunters had published hundreds of thousands of files, saying the state hadn't paid. In the copy TechCrunch reviewed, most were vehicle ownership records with buyer and seller names, addresses and VINs, and a smaller share included Social Security numbers, non-US passports and immigration papers. TechCrunch didn't find driver's licenses or photos, though Hackread's own analysis of the leak reported Social Security cards and licenses among the files.
A database built for police lookups was opened with a police department login, kept on a device it should never have been on.
7. DriveWealth: two days of access reached years-old Revolut records
Access September 4 to 5 · Customer notices from September 21, 2026 · Financial services / brokerage · United States · Actor unknown
DriveWealth, the US broker behind stock trading in apps such as Revolut, Stake and Hatch, says unknown attackers got into its network on September 4 and 5 through a social engineering campaign, and that it contained the compromise on September 5. Its notice to state regulators says the review finished on September 28 and confirmed that names and other personal information were taken. No passwords, card details or bank account details were involved, and DriveWealth found no unauthorized trades, transfers or withdrawals.
The exposed data may include names, contact details, postal addresses, employment details, country of citizenship, age, gender and partial account numbers. For Stake and Hatch users, it also included portfolio values and cash balances. DriveWealth hasn't given a total, but its notices list about 62,000 affected Rhode Island residents. Revolut says its European customers' records date from before December 2023, when it moved them off the DriveWealth arrangement, and that DriveWealth kept the data to meet regulatory obligations. It's the second incident to hit Revolut customers this month. On September 12, Revolut confirmed it had released customer data to scammers posing as government officials.
8. BigCommerce stores via Ribon: one third-party app key, one evening of downloads
Key misused September 13 · Revoked September 17 · Merchants notified from September 18, 2026 · E-commerce · United States / United Kingdom · Actor unknown
BigCommerce says it confirmed on September 17 that API credentials for the third-party apps Ribon and Ribon 1.5, run by Be A Part Of (a Fastr company), had been compromised through a breach at Fastr and used to inject malicious scripts into a small number of merchant storefronts. It removed the apps from affected stores, started notifying merchants on September 18, and says its own platform wasn't breached.
UK spirits retailer Master of Malt has published the most detailed account. On the evening of September 13, someone used Ribon's stolen key to download customer names, email addresses, phone numbers and postal addresses, page by page. The app's developer learned of the misuse on September 16, and the key was switched off on September 17. Passwords and payment details sit in a separate system that wasn't touched. Ribon was installed on hundreds of BigCommerce stores, Master of Malt says, but that's an install count, and nobody has said how many stores or shoppers were actually hit. Master of Malt has reported the incident to the UK Information Commissioner's Office.
What do September's breaches have in common?
Few of them needed a clever new exploit. Most came down to something the organization had stopped watching.
Start with access that was already handed out. Florida's attacker logged in with a real police account. The BigCommerce attacker used a real app key, and Master of Malt points out that only the app's developer or BigCommerce could have seen it being misused. DriveWealth's attackers talked their way in.
Then there are controls that were assumed to work. If the attackers' accounts are accurate, FBI Jobs sat behind a WAF rule that one encoded character defeats, and CenterPoint's customer API had no rate limiting to stop someone walking through millions of IDs.
And then there's data kept long after it was needed. Gyazo still held metadata for images deleted years ago. DriveWealth still held Revolut records from accounts that moved in 2023. IDScan and Times Car both stored images of government IDs, and attackers reached them.
What should security teams do now?
-
If you run PeopleSoft, apply Oracle's June 10 fix for CVE-2026-35273 and stop relying on a WAF rule. Search your logs for requests to /%50SEMHUB/, and rotate any credentials the PeopleSoft service account can read.
-
List every third-party app key on your commerce and SaaS platforms, cut each one's scope to what the app actually uses, and alert on bulk customer downloads.
-
Keep logins that can query sensitive records off personal devices, and put phishing-resistant MFA on them.
-
Rate-limit and monitor any public API that returns customer data by ID.
-
Set retention limits for identity documents and deleted content. Then check that "deleted" also removes the metadata.
A WAF rule or a "temporary" mitigation is an assumption until someone tries to get past it, and attackers will try encodings your rule never considered. That's the gap continuous testing closes. Strobes exposure validation runs those attempts against your own perimeter and APIs on a schedule, so you learn a compensating control has a hole before ShinyHunters does. Agentic pentesting covers the slower questions, like whether an endpoint leaks records when you iterate IDs, or what a single compromised account or app key can actually reach. It won't stop a phished employee, but it tells you how far one could get.
For earlier months, see the biggest data breaches of August 2026 and our month-by-month breach archive. For the vulnerabilities behind many of these incidents, read the latest top CVEs roundup.
FAQ
What was the biggest data breach of September 2026?
By claimed size, IDScan.net, where a seller says it has more than 153 million driver's license scans. IDScan has confirmed the breach but not the number. By company-confirmed count, Gyazo is the largest, with about 23.62 million user records and about 490 million image metadata records.
Did ShinyHunters really breach the FBI?
It's unconfirmed. The FBI says it's investigating unauthorized activity affecting FBIJobs.gov and hasn't determined the point of breach or confirmed data theft. The 2 to 3TB figure comes only from ShinyHunters.
What is CVE-2026-35273?
It's a CVSS 9.8 unauthenticated remote code execution flaw in Oracle PeopleSoft's Environment Management Hub. ShinyHunters exploited it as a zero-day from late May, Oracle patched it on June 10, and Google reported in September that the group is now bypassing WAF rules on systems that were never patched.
Were Revolut's own systems breached?
Not in the DriveWealth incident. The data was taken from DriveWealth's network, and Revolut says its own systems, passwords, card details and ID documents weren't affected. Revolut separately confirmed on September 12 that it had released some customer data to scammers posing as government officials.
Sources
1. IDScan.net
-
KrebsOnSecurity: FBI Probes Service Selling 153M+ Drivers Licenses
-
PCMag via Yahoo News: Company Behind Leak of Driver's Licenses Says Hacker Had Access for 5 Months
-
The Record: IDScan confirms breach after hackers offer 153 million driver's license scans for sale
-
Office of the Privacy Commissioner of Canada: news release, September 21, 2026
2. Gyazo
-
Helpfeel: Notice and Apology Regarding a Data Breach (Update 2)
-
The Hacker News: Gyazo breach exposes 23.62 million user records
-
Help Net Security: Hackers exploit Gyazo server flaw to steal 23.6 million user records
3. CenterPoint Energy
4. Times Car
-
MLex: Park24 says data breach could have affected up to 6.6m accounts
-
SC Media: Times Car confirms 6.6 million accounts compromised
5. FBI (FBIJobs.gov)
-
BleepingComputer: ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
-
The Hacker News: Attackers bypass WAFs to exploit Oracle PeopleSoft
-
eSecurity Planet: ShinyHunters bypasses PeopleSoft WAF in renewed exploitation
-
SecurityWeek: ShinyHunters claims FBI hack, demands retraction of threat report
6. Florida DMV (DAVID)
-
CSO Online: ShinyHunters claims Florida DMV breach, puts data on the clock
-
CyberGuy: DMV breach confirmed as hackers claim 200,000 records stolen
-
NewsBytes, summarizing TechCrunch: Massive data breach exposes details of Florida drivers
-
Hackread: Florida confirms DMV breach as ShinyHunters leak exposes SSN cards and licenses
7. DriveWealth
-
The Next Web: DriveWealth breach exposes data of Revolut customers who traded US stocks
-
Finance Magnates: DriveWealth security incident exposes Revolut, Stake and Hatch customer data
-
ClaimDepot: DriveWealth notice filed with the California Attorney General
