Data Breach Roundup (Sep 11 - 17, 2026)
Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach after the ShinyHunters extortion gang claimed to have compromised the system. FLHSMV determined that the attacker used compromised credentials belonging to a single Plant City Police Department user that had been improperly stored on the employee's personal electronic device. The attackers, however, claimed they exploited a password reset flaw to gain access to multiple DAVID accounts, including accounts belonging to DMV employees and an FBI agent.

Revolut confirms customer data breach through fake government requests
British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The exposed data included customers’ birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses. The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification. Revolut did not answer questions about how many people were impacted or in what markets.

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
It is unclear what VPN product was affected or the vulnerability exploited in the breach. The Japanese agency said in a separate Q&A that the issue had a medium severity rating and was not a zero-day. Potentially impacted data includes 236,000 names; 231,000 email addresses; 94,000 telephone numbers; and 1,000 physical addresses. Exposed individuals include government employees, public officials, and associated businesses and individuals who use the Government Solution Service system. The incident did not expose personal data of the general public, and the potentially compromised information does not include My Number identification numbers, bank-account details, or pension numbers.

CenterPoint Energy confirms customer data stolen in cyberattack
CenterPoint Energy is a Houston-based public utility company that provides electric and natural gas services with 7 million customers across Indiana, Minnesota, Ohio, and Texas. The attacker claims to have stolen 7.49 million records including names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers (SSNs).

Spain's data agency gets first report of AI-powered data breach
There's very little information about this breach like what company was impacted or how many people were impacted, or even exactly what information was affected. The organization reporting the incident said that the AI agent searched for flaws, logged into their systems, and then probed apps for additional security issues. In the final stages of the attack, the agent modified personal data and accessed financial documents.


Community Discussion