top of page

Top Data Breaches of September 2026: Biggest Cybersecurity Incidents

11 hours ago
8 min read

September 2026 brought breaches of almost every kind: a stolen media database offered for $15,000, a screenshot tool exposing millions of accounts, medical files belonging to FBI staff, and a seven-year-old vendor breach that finally reached a settlement.

The common thread was hard to miss. Again and again, the data left through someone else's system: a debt collector, a logistics provider, a vendor holding API credentials. Other incidents were extortion claims that the victims had not yet confirmed.

Here are the top data breaches of September 2026, what was exposed, and what security teams should take from them.

Note: Several incidents below involve attacker claims or ongoing investigations. Where an organization has not confirmed the scope, we describe the details as claimed or reported rather than as established fact.

September 2026 data breaches at a glance

Organization

Sector

Reported impact

Status

Condé Nast

Media

32.8M user records offered for sale

Not confirmed by company

Gyazo (Helpfeel)

Technology

23.62M user records; 490M image metadata records

Confirmed

FBI

Government

Personnel and medical records

Under investigation

Labcorp (AMCA)

Healthcare

10.2M patients; $2.3M settlement

Settled

Veradigm

Healthcare tech

3.5M records claimed by attackers

Incident confirmed; figure unconfirmed

Trezor (ShipMonk)

Crypto / logistics

81,000 customers

Confirmed

AECOM

Engineering

About 1.22TB claimed

Unconfirmed

Rohloff Group

Food service

536GB claimed

Incident confirmed; contained

Simba

Telecom

23,549 customers

Confirmed; resolved

 

1. Condé Nast: 32.8 Million User Records Offered for Sale

A database allegedly containing 32.8 million Condé Nast user records was put up for sale on a Russian-language cybercrime forum for $15,000. The seller claims it includes the full dataset behind the WIRED leak of December 2025.

The data reportedly includes:

•       Email addresses

•       Names

•       Postal addresses

•       Dates of birth

•       Gender

•       Phone numbers

Not every record contains every field, and the listing reportedly includes no passwords, password hashes or payment-card data. Researchers who reviewed a 5,000-record sample assessed it as genuine account data captured in late 2025. Condé Nast has not publicly confirmed the breach.

Why it matters: Even without passwords, a dataset linking names, email and home addresses and dates of birth at this scale is ideal raw material for targeted phishing and identity fraud.


2. Gyazo: 23.6 Million User Records Exposed

Helpfeel, the company behind the image-sharing service Gyazo, said an attacker exploited a vulnerability in its image upload server on September 11. The attacker was removed the next day, but not before reaching the database. Around 23.62 million user records were affected, including:

•       Names and email addresses

•       Password hashes

•       User and device IDs

•       X integration tokens

•       Profile, usage and billing information

The attacker also accessed metadata for roughly 490 million images, which could help reconstruct image URLs, along with a list of private images. Payment card data was not compromised. Helpfeel noted that the total includes anonymous accounts with no registered email address.

Why it matters: Screenshot tools routinely capture more than users intend, from internal dashboards to chat threads. Exposed image metadata turns that into a second-order risk, and leaked integration tokens can open connected accounts, so revoking them matters as much as resetting passwords.


Source: SecurityWeek

3. FBI: Personnel and Medical Records Claimed by ShinyHunters

The ShinyHunters group claims to have stolen data belonging to current and former FBI personnel, reportedly through the FBIJobs.gov portal and connected screening and medical systems. According to the BBC, the exposed information includes names, home addresses, phone numbers, badge numbers, job titles and spouse details. Samples seen by a BBC reporter also included highly sensitive medical records belonging to special agents.

Reuters reported that the group's haul includes psychiatric evaluations and medical test results, and partially authenticated some of the documents. The FBI says it is aggressively investigating, and ABC News reported that the point of compromise, whether a third party or the FBI's own systems, had not yet been determined. The attackers have threatened to publish more data.

Why it matters: For law enforcement staff, home addresses and family details are a physical safety risk, not just a privacy issue. Recruitment and background-check systems hold some of the most sensitive data any organization keeps, and they deserve protection to match.


4. Labcorp: $2.3 Million Settlement Over the AMCA Breach

On September 25, a coalition of 44 state attorneys general announced a $2.3 million settlement with Labcorp over the 2019 breach at its former debt collector, American Medical Collection Agency (AMCA). An attacker had access to AMCA's network from August 2018 to March 2019.

The wider AMCA incident affected more than 27.5 million people, including 10.2 million Labcorp patients and 451,558 Maryland residents. Exposed data across the incident included names, Social Security numbers, financial information, medical test information and diagnostic codes.

The settlement requires Labcorp to:

•       Extend its security program and incident response to cover vendor security events

•       Reduce unnecessary data sharing with third parties

•       Set up a dedicated team to assess and monitor vendor compliance

•       Require debt collectors to keep data inventories, meet contractual security standards, segregate data and undergo regular audits

•       Hire an independent assessor focused on vendor risk management

Why it matters: Seven years later, regulators are still holding the company that shared the data accountable, not just the vendor that lost it. AMCA itself went bankrupt. If your vendor is breached, the obligations remain yours.


5. Veradigm: Vendor Credentials Used to Copy Patient Data

Healthcare technology company Veradigm disclosed in a September 8 SEC filing that attackers used credentials obtained through an incident at a third-party vendor to access a Veradigm API used for customer services, then copied patient data. The company said a small number of its customers were affected.

Potentially exposed information includes names, addresses, phone numbers, email addresses and, for certain patients, Social Security numbers. Veradigm said clinical and medical information was not involved.

The Gentlemen threat group claims to have stolen 3.5 million patient records and has threatened to publish them. Veradigm has not confirmed that figure.

Why it matters: API credentials are keys to your data. When a vendor holds them, the vendor's security becomes part of yours, so scope them tightly, rotate them and monitor how they are used.


6. Trezor: ShipMonk Breach Grows to 81,000 Customers

Hardware wallet maker Trezor says a breach at logistics provider ShipMonk now affects about 81,000 customers, up from nearly 14,000 first disclosed in August, after 67,000 more US customers were identified. Attackers exploited a critical SQL injection vulnerability in Metabase, an analytics platform ShipMonk used.

Exposed information includes:

•       Full names

•       Email addresses

•       Phone numbers

•       Shipping addresses

•       Order numbers

Trezor says its own systems and wallet devices remain secure. It also says it had repeatedly received written assurance from ShipMonk that older customer data had been deleted. It had not been.

Why it matters: For crypto owners, a leaked shipping address points attackers to someone who probably holds digital assets, which raises the risk of phishing and even physical threats. Contractual deletion clauses need verification, not just a promise.


7. AECOM: Unconfirmed Claims of More Than 1TB Stolen


Engineering and infrastructure company AECOM faces unconfirmed breach claims from two groups. Metaencryptor claims to have stolen about 1.22TB of data. Separately, the monitoring service Breachsense reported a roughly 670GB AECOM leak attributed to BrainCipher.

AECOM has not confirmed either claim, and the scope, the data involved and the number of affected individuals remain unknown. A law firm has opened an investigation into potential class action claims.

Why it matters: For engineering firms, the exposure goes beyond personal data. Project files, designs and client information tied to public infrastructure can be sensitive in their own right.


Source: PR Newswire

8. Rohloff Group: INC Ransom Claims 536GB of KFC Franchise Data

Rohloff Group, one of Africa's oldest and largest KFC franchise operators, was hit by a ransomware attack. The INC Ransom group claims to have stolen 536GB of data across more than 103,000 files, most of it belonging to employees:

•       Bank statements

•       Identity documents

•       Disciplinary records

•       Company financial records

Rohloff says the incident has been contained with no disruption to restaurant operations. The attackers have already released samples and threaten to publish the full dataset.

Why it matters: Operations can keep running while the real damage sits on a leak site. Employee records are often less well protected than customer data, yet they carry the same identity-theft risk.


Source: MyBroadband

9. Simba: Identity Data of 23,549 Customers Exposed

Singapore telco Simba confirmed a data breach affecting 23,549 customers, discovered on September 24. The exposed information includes:

•       Names

•       Identity card numbers

•       Dates of birth

•       Mobile numbers

•       Email addresses

Simba said no credit card or bank account information was compromised and there is no indication the data has been misused. The company says the incident has been resolved and is notifying affected customers by email. Singapore's Personal Data Protection Commission is investigating.

Why it matters: An identity number combined with a mobile number is exactly what SIM-swap and account-takeover fraudsters look for, so telcos hold a particularly valuable combination of data.


Sources: The Business Times; Malay Mail

What September's breaches tell us

Third parties are the way in

Labcorp, Veradigm and Trezor were all exposed through a vendor: a debt collector, a supplier holding API credentials and a logistics provider running a vulnerable analytics tool. Your attack surface includes every organization you share data with.

Data you meant to delete still counts

Trezor's exposure grew because customer data from years earlier was never removed. Data that no longer serves a purpose is pure risk, and deletion needs to be verified.

Extortion claims arrive before confirmation

Condé Nast, AECOM, Veradigm and the FBI all faced public claims before the scope was confirmed. Organizations need to be able to assess a claim quickly and communicate clearly while the investigation continues.

Identity data is the prize

ID numbers, Social Security numbers, dates of birth and home addresses appeared again and again. Unlike passwords, they cannot be reset, which is why they fuel long-term fraud.

Regulators expect vendor oversight

The Labcorp settlement spells out what regulators now expect: vendor inventories, contractual security standards, monitoring, audits and independent assessment.

How to reduce your exposure

1.     Map your vendors and their data. Know which third parties hold your data or credentials, and rank them by sensitivity.

2.     Verify deletion. Require evidence that data has been destroyed when a contract ends or a retention period expires.

3.     Lock down API and service credentials. Scope them tightly, rotate them regularly and alert on unusual use.

4.     Patch the tools around your core systems. Analytics platforms, upload servers and integrations are frequent entry points.

5.     Collect and keep less. Data you don't hold can't be stolen.

6.     Prepare for vendor incidents. Include third-party breaches in your incident response plan and exercises.

How exposed is your organization through its vendors? Allendevaux & Company helps organizations assess third-party risk, test their defenses and prepare for incidents before they become headlines. Contact our team to review your security posture.

Frequently asked questions

What were the biggest data breaches of September 2026?

By volume, the largest were the alleged sale of 32.8 million Condé Nast user records and the Gyazo breach affecting 23.62 million user records. The claimed theft of FBI personnel and medical records was among the most sensitive.

Which September 2026 breaches involved third-party vendors?

Labcorp (through debt collector AMCA), Veradigm (through a vendor's compromised credentials) and Trezor (through logistics provider ShipMonk) were all exposed through third parties.

Were all of these breaches confirmed?

No. Condé Nast and AECOM have not confirmed the claims, and Veradigm has not confirmed the 3.5 million record figure. The FBI incident is still under investigation.

What should I do if my data was exposed in a breach?

Change reused passwords, turn on multi-factor authentication, watch for phishing that uses your personal details, and consider a credit freeze if identity numbers were exposed.

How can organizations reduce third-party breach risk?

Keep an inventory of vendors and the data they hold, set security requirements in contracts, verify data deletion, restrict and monitor vendor credentials, and include vendor incidents in response planning.

Comments


bottom of page