SecureFact – September 14, 2026
Major cybersecurity incidents impacted cryptocurrency, government, identity verification, healthcare, aviation, travel, and financial services organizations, exposing sensitive customer, driver, patient, traveler, and personal information while highlighting risks from third-party breaches, stolen credentials, social engineering, authentication flaws, and cloud security misconfigurations.
Brevo Email Provider Breach Affecting Trezor Users
Brevo, a third-party email marketing platform used by Trezor, suffered a confirmed security breach on September 9, 2026, affecting 120 Brevo customer accounts. The unauthorized attacker gained access to Brevo’s system and used it to send phishing emails from various customer accounts, including Trezor’s. The incident exposed approximately 347,000 email addresses from Trezor’s opt-in newsletter database. Trezor received fake “critical security alert” emails claiming a hardware microcontroller vulnerability in STM32 microcontrollers could expose wallet seeds to brute-force cracking. The phishing emails attempted to trick recipients into clicking malicious links that prompted them to download an app requesting wallet backup information. Trezor took down the malicious domain within 20 minutes, limiting the campaign’s impact to 2,500 customers who had clicked the link before takedown. The company suspended the Brevo account to prevent further email distribution and offered credit monitoring services to affected customers.
(Source: Read full report)
Florida DMV Database Breached Via Stolen Police Account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a data breach of its DAVID (Driver and Vehicle Information Database) on September 4, 2026, after the ShinyHunters extortion gang claimed to have compromised the system and stolen more than 200,000 driver records. Investigation determined that attackers used compromised credentials belonging to a single Plant City Police Department user that had been improperly stored on the employee’s personal electronic device. The breach exposed sensitive driver information including names, addresses, Social Security numbers, driver’s license IDs, and vehicle registration details. ShinyHunters initially claimed they exploited a password reset flaw to gain access to multiple DAVID accounts belonging to DMV employees and an FBI agent, then iterated through record IDs downloading associated HTML pages and images. The agency notified the Florida Office of the Attorney General and is working with the Florida Digital Service and Florida Department of Law Enforcement as part of its response. FLHSMV stated the breach was quickly mitigated and no further breach has occurred or is ongoing.
(Source: Read full report)
IDScan Confirms Breach Tied to 153 Million Stolen Driver’s Licenses
Identity verification company IDScan confirmed that hackers accessed customer data stored in its cloud platform, with the breach discovered around September 1, 2026. The company learned that an unauthorized third party “may” have accessed or copied customer information stored within accounts on the IDScan.net cloud, including full names, driver’s license numbers, and other government-issued identification numbers. The breach reportedly allowed threat actors to steal scans of driver’s licenses from a massive database containing more than 153 million driver’s license scans, along with 10 million ID cards, 3 million travel documents, and 579,000 medical cards. IDScan provides identity verification technology used by car rental companies, retailers, financial institutions, cannabis dispensaries, gun shops, and hospitality businesses. Upon discovery, IDScan took immediate steps to secure systems and engaged third-party specialists to determine the full scope of the incident. The company is cooperating with federal law enforcement, with the FBI confirming it was investigating the incident. IDScan is notifying potentially impacted individuals and providing free credit monitoring and identity protection services.
(Source: Read full report)
AdaptHealth Confirms 4.1 Million People Exposed in July Cyberattack
Healthcare company AdaptHealth confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July 2026, attributed to the ShinyHunters threat group. The company provides home medical devices, supplies, and related services including sleep-apnea and respiratory equipment, oxygen therapy, hospital beds, and mobility products. The breach occurred on June 5, 2026, through a successful social engineering ploy that compromised the privileged account of a third-party contractor, providing access to cloud-based business applications including internal patient management systems, document storage platforms, and electronic health record system portals. Exposed data included full names, contact information, demographic information, health insurance information, and health information. On June 15, an unnamed threat actor contacted AdaptHealth demanding ransom in exchange for not leaking the stolen data. AdaptHealth found no evidence of identity theft, fraud, or other misuse of the stolen data. Impacted individuals received data breach notifications with instructions on how to enroll in a free 12-month credit monitoring and identity protection service. AdaptHealth served approximately 4.1 million patients across all 50 U.S. states through a network of 680 locations.
(Source: Read full report)
Veradigm Warns of Patient Data Breach After Ransomware Gang Claims Attack
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients’ personal data. The company says the incident did not cause operational disruptions but affected a small number of customers. An attacker obtained credentials from a vendor’s environment for a Veradigm API reserved for customer services and used their access to copy patient data. The stolen data includes personal details and Social Security numbers (SSNs) for some patients, while clinical or medical information remained safe. The compromised credentials provided access only through that limited interface and did not provide access to any other part of Veradigm’s environment, including the broader network, servers, databases, or other systems. After discovering the breach, Veradigm initiated incident-response procedures, notified law enforcement, and is investigating to determine the scope. Affected customers and individuals are being notified with credit-monitoring services offered where applicable. The Gentlemen ransomware group claimed the intrusion on September 5 and listed the company on its data leak site, alleging to be holding 3.5 million patient records including full names, home addresses, SSNs, email addresses, phone numbers, and personally identifiable information of guarantors.
(Source: Read full report)
220 Million Traveler Records Exposed in Vietnam-Linked APIS Leak
An Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records was accessible online through a chain of security misconfigurations, with the system appearing linked to a Vietnamese organization. The exposed records span January 2017 to April 2026 and could involve travelers of many nationalities who flew to, from, or through Vietnam during that period. Kinryū Labs discovered the Elasticsearch cluster on June 3 while surveying exposed databases as part of research into ransomware activity. The cluster contained 29 indices and roughly 107 GB of data, with two principal indices holding 210,318,069 passenger records and 10,465,631 crew records for a combined 220,783,700 entries. Exposed information included passengers’ and crew members’ names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, issuing countries, flight numbers and dates, airlines, departure and destination airports, seat assignments, baggage references, and flight times. The database was accessible through a cloud-based path that accepted default credentials. Kinryū Labs reported the issue to Vietnamese authorities, airlines represented in the database, and national computer emergency response teams beginning June 3, with access remediated on June 8. It remains unclear whether the database was downloaded, sold, ransomed, or otherwise exploited by malicious actors before being secured.
(Source: Read full report)
Revolut confirms customer data breach through fake government requests
Revolut has confirmed a customer data breach in which attackers used fake government requests to trick the company into sharing customer information. Rather than directly hacking Revolut’s systems, the attackers exploited trust by making the requests appear to come from a legitimate government agency. Some sensitive customer information was disclosed to an unauthorized party, although Revolut said customer funds and its core systems were not affected. The company blocked the malicious email address, notified the relevant authorities and regulators, and investigated the incident. The breach highlights how sophisticated social-engineering attacks can bypass traditional security controls and why organizations need stronger verification and approval processes for sensitive data requests.
(Source: Read full report)