Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen
Canada's Hospital for Sick Children reported a data theft incident exposing current and former employee data via a third-party application.
The Hospital for Sick Children (SickKids), Canada's largest pediatric health center, disclosed that hackers stole personal information of current and former employees, job applicants, and SickKids Foundation staff, likely through a third-party software application. The attack briefly took down the hospital's careers website but did not involve clinical systems or patient information. Affected individuals were notified and offered two years of credit monitoring. The hospital was previously hit by ransomware in 2022.
Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
Attackers using a compromised Italian government PEC account impersonated law enforcement to obtain data on ~680 Revolut customers.
Revolut confirmed its systems were not breached; fraudulent data requests came from a compromised PEC mailbox tied to the Prefecture of Reggio Calabria on the pec.interno.it domain. Per the Financial Times, roughly 680 customers had identity documents, addresses, banking information, verification selfies and cryptocurrency transaction histories exposed. Researcher Korra of Duel described a 'spray and pray' operation using hundreds of crypto transaction IDs and fraudulent European Investigation Orders. Threat actor IAmNotAVillain claims six months of access and 147 GB exfiltrated from Italian law-enforcement systems, though this remains unverified.
CenterPoint Energy Confirms Data Breach Exposing Customers’ Personal Information
CenterPoint Energy confirmed an unauthorized third party accessed customer personal data via an external system, disclosed in an SEC Form 8-K filing.
CenterPoint Energy disclosed in a September 14, 2026 Form 8-K that an unauthorized third party obtained personal information of some customers through one of the company's external systems. The company learned of the incident after an online post claimed possession of a customer dataset, then activated incident-response protocols and engaged external forensic specialists. Electric and gas delivery operations were unaffected and the company does not expect a material financial impact, though response, notification, and compliance costs are being incurred. The number of affected customers, data types, and threat actor remain undisclosed as the investigation continues.
Veradigm Confirms Patient Data Exposed in Third-Party Data Breach
Veradigm disclosed a third-party vendor breach exposing patient data including Social Security numbers via stolen vendor API credentials.
Veradigm filed an 8-K with the SEC on September 8, 2026, disclosing that attackers used credentials stolen from a third-party vendor to access a specific vendor-facing API and download patient personal data, including Social Security numbers for some individuals. No clinical or medical information was compromised, and Veradigm's internal infrastructure was not breached directly. The company activated incident response, notified law enforcement, and is offering credit monitoring to affected individuals.
Security Incident – BGP Hijacking
Attackers BGP-hijacked Softaculous' Hetzner IP block for 33 hours, obtained valid TLS certificates, and delivered a malicious Virtualizor update to some servers.
Between August 28 and 30, 2026, AS62390 (NexonHost) announced 162.55.80.0/24 via transit AS6204 (Zet.net) without authorization, diverting traffic while retaining Hetzner's AS24940 on the AS path. The attacker obtained valid Let's Encrypt certificates for virtualizor.com domains because the CA's domain validation was also routed through the hijack, so affected connections showed no TLS warnings. A malicious Virtualizor update package reached a handful of installations; routing was fully restored, and reconstruction from RIPE RIS data showed all 368 collector peers carried the hijacked route at some point with roughly 28% time-weighted diversion.
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
METR disclosed attackers stole an API key and burned about $600,000 in inference credits, plus a second probing campaign against its infrastructure.
METR, the AI model evaluation non-profit, disclosed two 2026 security incidents. In March, attackers found a publicly exposed EC2 instance behind a fail-open authentication bug, prompted an agent to reveal its API key, added SSH persistence, and consumed roughly $600,000 in inference credits over three weeks. In May, a likely financially motivated actor systematically probed METR's public infrastructure using agents for vulnerability discovery, credential stuffing, OAuth token grants and staff phishing, with no confirmed access to non-public data.
A Cautionary Tale About Data Breach Claims, Verification and Carhartt
Troy Hunt cautions that claimed Carhartt breach data requires verification, warning that criminals' breach claims are not always accurate.
Troy Hunt published a cautionary tale about data breach claims, verification, and apparel brand Carhartt. He argues that claimed breaches from cybercriminals should not be taken at face value and may stem from errors by the criminals themselves. The piece underscores the need to verify breach data before treating it as authentic, in the vein of Have I Been Pwned's validation practices.
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
Week in review: Medusa ransomware hit 500+ orgs per CISA, millions of Azure tenant records allegedly stolen, SafePal and French tax authority breaches disclosed.
Help Net Security's weekly roundup covers the FBI, CISA, and HHS joint advisory update reporting Medusa ransomware has breached more than 500 organizations since June 2021, and threat actor TheHatman's claim of millions of employee records stolen from Azure tenants of Fortune 500 firms including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services, per Hudson Rock. It also covers the SafePal breach affecting 39,798 customers, France's DGFiP breach exposing data on 678,000 individuals, and UT San delaying its fall semester after a cyberattack. Security items include critical unauthenticated GitLab flaw CVE-2026-19478, an actively exploited patched macOS Screen Sharing flaw deploying a cryptominer, US charges against 17 Mabna Institute Iranian hackers over 31TB of stolen academic data, and Google Mandiant's AI agents finding 100+ high-severity vulnerabilities.
Hackers target Ukrainian agency managing assets seized from sanctioned Russians
Ukraine's ARMA asset agency reported a cyberattack amid selecting a manager for seized IDS Ukraine assets linked to sanctioned Russians.
Ukraine's Asset Recovery and Management Agency (ARMA), which manages assets seized from criminals and sanctioned individuals, said Tuesday it had been targeted by a cyberattack, with the SBU investigating. The attack coincided with preparations to select a manager for seized corporate rights in IDS Ukraine, a major beverage producer seized in late 2022 from Russian shareholders including sanctioned billionaire Mikhail Fridman. ARMA reported other suspected interference since spring, including unauthorized access to an internal database of agency officials, but did not attribute the attack or release technical details. In April, ARMA employees were targeted in a cyberespionage campaign attributed to Russia-linked APT28, which failed to penetrate internal systems.
SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
SafePal disclosed an order-tracking plug-in authorization flaw exposing names, emails, addresses and purchase details of 39,798 hardware wallet customers; no wallet credentials affected.
Hardware wallet maker SafePal disclosed that an authorization flaw in an order-tracking plug-in exposed names, email addresses, shipping addresses, phone numbers and purchase details of approximately 39,798 customers. No seed phrases, private keys, wallet credentials or financial information were exposed, and SafePal found no evidence of wallet or fund compromise. A separate configuration error left a data-cleanup process broken between September 2025 and April 2026, extending the affected order window back to March 2025. A threat actor has advertised a matching dataset on a cybercrime forum, and the company has fixed the flaw, cut data retention to 90 days, purged affected records, engaged third-party validators and taken down over 30 phishing sites.