Data Breach Roundup (Sep 4 - 10, 2026)
Trezor data breach impact now reaches 81,000 customers
Cryptocurrency hardware wallet has suffered yet another data breach. This one was initially disclosed in August and said to impact 14,000 customers including full names, shipping addresses, email addresses, and phone numbers. Now Trezor has disclosed an additional 67,000 US customers because their shipping provider was not deleting customer data despite being required to by Trezor.

Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor warned on Wednesday that threat actors had breached Brevo, its third-party email provider, and were emailing customers who opted in to receive newsletters. We now know that the attackers conducted phishing attacks against 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. According to customers targeted in this phishing campaign, they received fake "critical security alert" emails from [email protected] claiming that a "hardware microcontroller vulnerability" in Trezor cold storage wallets' STM32 microcontrollers could expose their seeds to brute-force cracking.

Mathspace discloses data breach affecting over 1 million people
Mathspace is an online math learning platform used in thousands of schools across Australia, New Zealand, the US, and the UK. The compromised access took place between August 10 and August 27, and impacted students and staff from Australia and New Zealand (as well as parents and guardians). The article didn't specify what data was impacted.

220 million traveler records exposed in Vietnam-linked APIS leak
An Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records was accessible online through a chain of security misconfigurations. The article says that APIS's are used worldwide to collect identity, passport, and flight information from airlines before passengers and crew arrive at or depart from a country. The exposed records span January 2017 to April 2026. The exposed information included passengers' and crew members' names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries. Associated travel data included flight numbers and dates, airlines, departure, destination and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times, information typically carried by APIS and related airline systems.

ShinyHunters hackers claim breach of Florida "DAVID" DMV database
DAVID is the "Driver and Vehicle Information Database" platform operated by the Florida Highway Safety and Motor Vehicles (FLHSMV) agency, used by law enforcement and officials to look up information about a particular driver. As proof of the breach, the threat actors released a screenshot of Jeffrey Epstein's record in the DAVID system. This record includes the person's address, Social Security number, birth date, driver's license ID, issuance and expiration dates, and registered vehicles. The system also has tabs for additional information, including driver's license transactions, addresses, insurance, prior vehicles, and parking permits. They claim to have stolen 200,000 records. (I would also like to note that DAVID was one of the tools a Florida police officer recently used to stalk a woman after she turned him down for a date.)

Veradigm warns of patient data breach after ransomware gang claims attack
Veradigm is a Chicago-based healthcare technology company that supplies medical practices with electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software. The threat actor alleges to be holding 3.5 million patient records that include full names, home addresses, SSNs, email addresses, phone numbers, and personally identifiable information or guarantors.

AdaptHealth confirms 4.1 million people exposed in July cyberattack
AdaptHealth provides home medical devices, supplies, and related services, including sleep-apnea and respiratory equipment, oxygen therapy, hospital beds, and mobility products. The breach impacted full names, contact information, demographic information, health insurance information, and health information.

ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen
IDScan has finally confirmed what we all knew. Stolen information includes people’s full names and driver’s license numbers, along with identity numbers from other government-issued documents, such as passports. As usual, the breach announcement page has a noindex tag.


Community Discussion