Data Breach Roundup (Sep 25 - Oct 1, 2026)
Some Supabase customers are publicly exposing reams of people’s data to the web
Supabase is a hosting platform popular with vibe-coded apps. Cybersecurity firm Upguard said that they found around 16,000 database exposing data like names, addresses, phone numbers, and passwords.

Times Car confirms data breach affecting 6.6 million user accounts
Times Car is a Japanese car-sharing service. The attacker had access to the company systems for nearly a month. Exposed data includes full names, department name (for corporate members), physical address, date of birth, telephone number, email address, driver's license information, identity verification document information (such as images of driver's licenses), account password, and linked service IDs.

Highly Sensitive Data of 3 Million in the People in the Pentagon's System Accessed by "Unauthorized Users"
The Pentagon is sending out letters to affected individuals informing them that the Defense Manpower Data Center was accessed by "unauthorized users." This includes both civilian and active-duty Department of Defense employees, veterans, retirees, and family members. Impacted data includes Social Security numbers, names, dates of birth, contact information, sex, race, and military personnel information such as occupational specialty. The data was accessed for about 9 months between October 2025 and the discovery on July 16, 2026 and it was stored completely unencrypted.


Community Discussion