SecureFact – September 21, 2026
Major cybersecurity incidents impacted technology, energy, government, financial services, and enterprise organizations, exposing millions of user, customer, personnel, financial, and business records while highlighting risks from server vulnerabilities, exposed APIs, VPN flaws, social engineering, and third-party access.
Gyazo server flaw exploited to steal 23.6 million user records
Gyazo, a cloud-based screenshot and screen-recording platform with 23 million users, suffered a major data breach on September 11, 2026, when hackers exploited a server vulnerability to access its database and steal approximately 23.62 million user records. The company detected suspicious activity on September 12 and immediately fixed the vulnerability, but the data had already been exfiltrated. The exposed data includes names/nicknames, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile details, subscription information, and billing status. Additionally, 490 million image metadata records were compromised, including image IDs, upload IP addresses, User-Agent strings, EXIF location data, OCR-extracted text, image titles, source URLs, and hashed passphrases for private images. Gyazo temporarily disabled access to files whose records were exposed and notified affected users directly. The company contacted authorities and engaged external experts to investigate the incident. All users are advised to change their passwords on Gyazo and other platforms where they use the same credentials.
(Source: Read full report)
CenterPoint Energy confirms customer data stolen in cyberattack
CenterPoint Energy, a Houston-based utility company serving approximately 7 million metered customers across Indiana, Minnesota, Ohio, and Texas, disclosed a data breach affecting 7.49 million customer records. A threat actor using the alias “4d722e4d656f77” claimed to have stolen the data by exploiting CenterPoint’s public API, which lacked rate limiting, web application firewall (WAF) protection, and other security measures against automated access. The compromised data includes names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers (SSNs). The attacker leaked the data online after claiming the company ignored their messages. CenterPoint Energy confirmed the breach in an SEC filing, stating that an unauthorized third party obtained personal information relating to a portion of the company’s customers through an external-facing system. The company activated incident-response procedures, hired third-party cybersecurity experts, strengthened protections on its systems, and reported the incident to law enforcement and regulators. Multiple class-action lawsuits have been filed against the firm by law firms representing potentially impacted customers.
(Source: Read full report)
Japan’s Digital Agency says VPN flaw exposed 246,000 personnel records
Japan’s Digital Agency discovered a data breach exposing approximately 246,000 record rows containing personal information of government employees after attackers exploited a vulnerability in a VPN device used by the Government Solution Service (GSS). The investigation began on June 25 after detecting large-scale file access from a maintenance staff member’s account. On July 9, the agency discovered that a third party had used a VPN vulnerability to gain unauthorized access to the system. The exposed data includes 236,000 names, 231,000 email addresses, 94,000 telephone numbers, and 1,000 physical addresses of government employees, public officials, and associated businesses and individuals using the GSS system. The compromised information does not include My Number identification numbers, bank-account details, or pension numbers. The agency suspended the affected account, cut off communication between the compromised equipment and the outside world, and prevented further unauthorized access. No cases of actual misuse of the impacted information have been detected, though the agency warned about elevated risks of impersonation and phishing. The Digital Agency notified Japan’s Personal Information Protection Commission and set up a dedicated support line for affected individuals.
(Source: Read full report)
Revolut discloses data breach exposing financial info, passports
Fintech company Revolut, operating in over 160 countries with more than 80 million customers worldwide, disclosed a data breach after a threat actor impersonating a government agency requested and received personally identifiable information (PII) via email. The attacker used valid domain authentication credentials to make the request appear legitimate, and Revolut fulfilled it under the reasonable belief it was an authentic government agency request. The exposed data includes affected individuals’ identity details (full name, date of birth, occupation), contact details (postal address, email address, telephone number), and document/verification data such as copies of identity documents (passport and/or driver’s license) and facial verification images (selfies provided for Know Your Client verification). The breach also exposed account statements (including IBAN numbers), withdrawal records, and full transaction history (including Bitcoin transactions). Revolut confirmed the breach affects a limited number of customers but refused to share an exact number. Upon detection, the company immediately blocked the address, alerted relevant government agencies, enforcement agencies, data protection authorities, and financial regulators. Revolut systems and customer funds remain unaffected. Crypto fraud investigator ZachXBT indicated the breach likely targeted high net worth users.
(Source: Read full report)
Canva breach affects data linked to 424 organizations in Türkiye
A data breach involving Canva has affected data linked to 424 organizations and institutions in Türkiye after attackers gained unauthorized access through a third-party tool used by Canva. The exposed information reportedly includes employees’ names, business email addresses, workplace locations, and business phone numbers, as well as customer order forms, contracts, invoices, data protection agreements, and other business correspondence shared with Canva. The number of individuals affected has not yet been determined. Canva stated that its main platform, user accounts, passwords, designs, and content were not compromised, and that it removed the third-party tool’s access after discovering the incident. The Turkish Personal Data Protection Authority (KVKK) is continuing its investigation.
(Source: Read full report)