Data Breach Roundup (Sep 18 - 24, 2026)

Data Breach Roundup (Sep 18 - 24, 2026)

Gyazo server flaw exploited to steal 23.6 million user records

Gyazo is a cloud-based screenshot, screen-recording, and image-sharing platform popular in the gaming community. The incident occurred on September 11 and impacted names/nicknames, email addresses, hashed passwords, user & device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile details, subscription information, billing status, and usage statistics. It also exposed anonymous account records and 490 million image metadata records, mostly from images uploaded prior to January 19.

Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records.

BigCommerce alerts merchants of data breach linked to Ribon apps

BigCommerce is a third-party Software-as-a-Service ecommerce platform. They suffered a "credential compromise" on September 17. The breach impacted Master of Malt and several other unnamed retailers. Master of Malt said shopper full names, email addresses, phone numbers, and shipping postal addresses were impacted. Little else is known at this time.

BigCommerce alerts merchants of data breach linked to Ribon apps
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores.

‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees

ShinyHunters is claiming they have agent names, home addresses, phone numbers, date of birth, and information on their spouses for all FBI employees and applicants. BleepingComputer reports that the attackers breached Oracle PeopleSoft using a zero-day then moved into AWS and stole between 2-3TB of data.

‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees
A sample of 5,000 alleged agents seen by 404 Media includes names, addresses, phone numbers, and details on FBI employees’ spouses.

Sweden fines Miljödata $183,000 over breach affecting 2.2 million

Miljödata is a Swedish software company that develops and provides work environment and HR management systems used by 80% of Sweden’s municipal systems. They suffered a cyberattack in August 2025 which disrupted services in over 200 regions and impacted residents' sensitive data including personal identity numbers, contact information, sickness absence, rehabilitation, and school incidents involving underage individuals.

Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Sweden’s data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people.

Community Discussion