Data Breach Roundup (Sep 25 - Oct 1, 2026)

Data Breach Roundup (Sep 25 - Oct 1, 2026)

Some Supabase customers are publicly exposing reams of people’s data to the web

Supabase is a hosting platform popular with vibe-coded apps. Cybersecurity firm Upguard said that they found around 16,000 database exposing data like names, addresses, phone numbers, and passwords.

Some Supabase customers are publicly exposing reams of people’s data to the web | TechCrunch
The findings highlight how AI-generated and vibe-coded apps can spill and expose users’ data when not configured or secured properly.

Times Car confirms data breach affecting 6.6 million user accounts

Times Car is a Japanese car-sharing service. The attacker had access to the company systems for nearly a month. Exposed data includes full names, department name (for corporate members), physical address, date of birth, telephone number, email address, driver's license information, identity verification document information (such as images of driver's licenses), account password, and linked service IDs.

Times Car confirms data breach affecting 6.6 million user accounts
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week.

Highly Sensitive Data of 3 Million in the People in the Pentagon's System Accessed by "Unauthorized Users"

The Pentagon is sending out letters to affected individuals informing them that the Defense Manpower Data Center was accessed by "unauthorized users." This includes both civilian and active-duty Department of Defense employees, veterans, retirees, and family members. Impacted data includes Social Security numbers, names, dates of birth, contact information, sex, race, and military personnel information such as occupational specialty. The data was accessed for about 9 months between October 2025 and the discovery on July 16, 2026 and it was stored completely unencrypted.

Highly Sensitive Data of 3 Million in the People in the Pentagon’s System Accessed by “Unauthorized Users”
The Pentagon sent out letters to affected individuals explaining that their Defense Manpower Data Center (DMDC) was accessed by “unauthorized users,” exposing the highly sensitive personal data of millions of military personnel.

Community Discussion