Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen
CenterPoint Energy confirmed a breach after a hacker claimed stealing 7.49 million customer records, including partial Social Security numbers, via an unprotected API.
CenterPoint Energy disclosed in an SEC 8-K filing that an unauthorized third party obtained personal information of a portion of its customers through an external-facing system. A threat actor using the alias '4d722e4d656f77' claimed on a cybercrime forum to have extracted over 7.49 million records, including names, addresses, account numbers, billing data, and partial Social Security numbers, via an API lacking authentication, rate limiting, and WAF protection. The company confirmed the breach but not the record count; energy services were unaffected and the investigation is ongoing.
ShinyHunters claims Florida DMV breach, puts data on the clock
ShinyHunters claims it breached Florida DMV's DAVID database, stole 200,000+ driver records including SSNs, and set a September 11 extortion deadline.
The ShinyHunters extortion group claims it breached the Florida Department of Highway Safety and Motor Vehicles' DAVID driver and vehicle database and stole more than 200,000 records. As evidence it published a screenshot of a Jeffrey Epstein record showing address, Social Security number, date of birth, license number and registered vehicles, and set a September 11 deadline before publication. The group says it obtained access through a password-reset weakness, compromised employee accounts, and queried and downloaded driver records and images. The Florida DMV has not confirmed the claim; it follows a separate confirmed IDScan.net breach exposing over 153 million license scans that prompted an FBI investigation.
Extortion Group FulcrumSec Claims 86GB Manchester Airports Data Theft
Extortion group FulcrumSec claims stealing 86GB of Manchester Airports Group data, exposing 8.7 million customers' personal and booking details.
Manchester Airports Group disclosed a breach on August 27 affecting parking, lounge, Fast Track and WiFi registrations at Manchester, London Stansted and East Midlands airports, impacting 8.7 million customers, most exposed only email addresses. FulcrumSec claims it stole about 86GB via airport-specific Iterable API credentials exposed in client-side JavaScript, including a 21.5GB Manchester export with booking histories, marketing data and nearly 200,000 records on upcoming 2026 travel. BleepingComputer verified sample records against a real traveler's Fast Track history; MAG declined to address the group's specific claims. Researchers warn the combination of UK postcodes, vehicle registrations and booking details could enable convincing targeted phishing, and MAG says no payment card or banking data was exposed.
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
FulcrumSec leaked ~549GB of Manchester Airport Group data, claiming 8.7M customer profiles exposed via exposed Iterable admin keys.
FulcrumSec posted around 549GB of uncompressed stolen Manchester Airport Group (MAG) data on its leak site, claiming nearly 8.7 million customer profiles with email, name, phone, home town, postcode and residential IP. The group said initial access came from Iterable platform admin keys exposed in the root-domain JavaScript of the Manchester, Stansted and East Midlands airport websites. Allegedly stolen data also includes ~1.2 billion marketing events, 2.5 million bookings, 461,000 SMS records, 108,000 vehicle plates and ~191,000 future bookings. MAG has provided no update since August 27 and the claims remain unverified.
France investigates tax authority breach after hacker claims 600,000 victims
France's tax authority DGFiP confirmed hackers extracted data on individuals and businesses; a hacker claims more than 600,000 victims.
France's Economy Ministry said an attacker gained unauthorized access to DGFiP systems in late June by stealing or misusing someone's identity, viewed and extracted data, and was cut off after detection. A hacker using the alias ZeroBytes claimed via FrenchBreaches to have taken data on over 600,000 people, including names, tax identification numbers, emails, family circumstances and tax status; the claim is unverified. The DGFiP will notify affected individuals, report to France's data protection authority and file a criminal complaint. It follows other 2026 breaches at ANTS, the Education Ministry and the National Bank Accounts File.
Russian network monitoring firm confirms cyberattack claimed by pro
Russian firm Microolap confirmed hackers hit non-critical systems, disputing pro-Ukraine group Black Spark's claims of access to core platform and customer data.
Russian network monitoring software developer Microolap confirmed hackers compromised several rarely used development systems, an outdated website, and an old Bitrix24 customer management system, but denied claims that attackers reached its EtherSensor platform or stole data from customers like Russian Railways, Goznak, and VTB Bank. The pro-Ukraine group Black Spark claimed a month-long intrusion with data extraction and deletion, publishing screenshots Microolap disputes. The company isolated affected systems and engaged an unnamed major Russian cybersecurity firm for investigation.
Hacker claims millions of records stolen from corporate Azure tenants
Threat actor TheHatman claims millions of employee records stolen from Azure tenants of nine Fortune 500 firms, including McDonald's, Vodafone, Kyndryl, and TCS.
A threat actor known as TheHatman posted large internal employee directories on cybercrime forums over the past week, claiming each was pulled directly from the victim organization's Azure tenant. McDonald's tops the list at roughly 1.7 million records, followed by TCS (~800,000), Vodafone (~425,000), and HCL (~250,000), with IHG, Kyndryl, Gap, Hexaware, and Wyndham also named. Hudson Rock found samples consistent with standard Azure directory exports and suspects infostealer-derived credentials rather than a systemic Azure zero-day. TCS filed a statement with the Bombay Stock Exchange saying it found no credible evidence of a breach and the data appears over four years old.
ShinyHunters claims it stole 284 million patient records from McKesson
ShinyHunters claims theft of 284 million patient records from McKesson via vishing, Okta takeover, and Salesforce/Snowflake access, demanding $55,236,150.
McKesson disclosed in an SEC filing a cybersecurity incident detected August 25, 2026, involving unauthorized access to third-party applications and data exfiltration affecting a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. ShinyHunters told BleepingComputer it entered through vishing calls to employees, used stolen credentials to take over Okta single sign-on accounts, and extracted about a terabyte of data from Salesforce and Snowflake environments over four days. The group claims 284 million database rows including names, addresses, Social Security numbers, Medicaid details, medical record numbers, and medication data, and demanded $55,236,150 with a 72-hour deadline; none of these claims have been independently verified.
McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen
A seller offers 1.7 million McDonald's employee records allegedly taken from its Azure tenant via compromised credentials; an 8,000-row sample verifies as genuine.
A forum seller named TheHatman posted an 8,000-row sample of McDonald's employee directory data, claiming a 1.7 million-record haul pulled directly from the company's Azure tenant using compromised credentials. Ransomnews analysis found authentic Entra ID export artifacts, including genuine domains, tenant-internal addresses, encoding errors, and truncated HR fields, but could not verify the data's age or the 1.7 million figure. The same seller listed nine datasets in 16 days covering about 3.6 million records across McDonald's, Vodafone, Gap, hotels, and IT outsourcers, suggesting infostealer-driven credential resale. No passwords or hashes appear in the sample, so the primary risk is social engineering.