CenterPoint Energy Data Breach – Hackers Stolen Customer’s Personal Data
CenterPoint Energy confirmed via SEC 8-K filing that an unauthorized third party stole customer personal data from an internet-facing system.
Houston-based utility CenterPoint Energy disclosed a breach in a Form 8-K filed September 14, 2026, after an online post claimed to offer a dataset of customer information. The company confirmed an unauthorized party accessed personal information for a portion of its customer base via an internet-facing system, but has not disclosed how many individuals were affected or what data types were exposed. Investigation with external forensic experts is ongoing, law enforcement and regulators have been notified, and electric and gas delivery operations remain unaffected. CenterPoint does not expect a material financial impact but warned the scope could grow as the review continues.
Japan’s Digital Agency Breach Exposes 240,000+ Users’ Personal Records to Hackers
Attackers exploited a patched VPN appliance flaw to breach Japan's Digital Agency shared government platform, exposing about 246,000 personal records.
Japan's Digital Agency disclosed on September 11 that attackers exploited a VPN appliance vulnerability to access the Government Solution Service (GSS), a shared IT platform across ministries, exposing roughly 246,000 personal records. The attacker was active since late May using a maintenance staffer's credentials, with suspicious activity detected June 25 and containment on July 9. Exposed data covers about 189,000 employees/public officials and 57,000 contractors; no My Number, bank, or pension data was included. The VPN flaw was medium severity with a patch already available, and the 78-day detection-to-disclosure gap has drawn scrutiny.
Revolut Data Breach Via Fake Government Requests – What We Know So Far
Revolut confirmed attackers extracted customer KYC records by sending fraudulent data requests from a spoofed or compromised government agency email domain.
Revolut confirmed a data breach in which an unauthorized party obtained sensitive customer records by submitting fraudulent information requests from an email account on a legitimate government agency domain with valid SPF/DKIM/DMARC authentication. Disclosed data could include full names, dates of birth, passport or driving-license copies, onboarding facial images, IBANs, account statements, withdrawal records, and complete transaction histories including Bitcoin activity. Crypto investigator ZachXBT assessed the operation targeted high-net-worth users, while a threat actor using the name 'IAmNotAVillain' claimed Italian law-enforcement departments were compromised over six months with 147 GB of material, claims that remain unverified. Revolut says only a limited number of customers were affected, blocked the email address, and notified regulators and affected customers, stating its systems and funds were not compromised.
Revolut handed customer data to fraudsters using government email account
Revolut handed sensitive KYC data of high-net-worth crypto customers to fraudsters submitting fake emergency data requests from a compromised government email domain.
Revolut confirmed it disclosed sensitive customer data—including passport and driver's license copies, verification selfies, bank statements, IBANs, and Bitcoin transaction histories—to attackers who submitted fraudulent emergency data requests from a legitimate government agency email account, apparently an Italian domain. Targets were high-net-worth individuals involved in crypto, including Marc Karpelès and entrepreneur Marc Zeller. A Telegram account claiming responsibility posted stolen data as proof and demanded an extortion payment; the account has since been suspended. Revolut says only a limited number of customers were affected and has alerted the relevant government agency, law enforcement, and regulators. The technique mirrors 2021-2022 Lapsus$-linked fraudulent emergency data request scams against Apple, Meta, and Discord.
Revolut Data Breach Exposes Customers’ Passport Copies and Full Transaction Histories to Hackers
Revolut leaked KYC documents and full transaction histories after a fraudulent, domain-authenticated email request impersonating a government agency.
Revolut disclosed that an attacker using an unauthorized email account on a legitimate government domain, with valid domain-authentication credentials, tricked the fintech into releasing customer data. The exposed data includes passport and driver's license copies, identity-verification selfies, full names, dates of birth, addresses, IBANs, and complete transaction histories including Bitcoin activity. Revolut says core systems, accounts, and funds were not compromised, and it blocked the email source and notified authorities. On-chain investigator ZachXBT and others indicated the operation targeted high-net-worth users facing elevated phishing, SIM-swap, and extortion risk.
US and Canadian court data exposed in Thomson Reuters breach
Thomson Reuters disclosed a breach of its C-Track court platform exposing sealed court records and personal data across 12+ US states and Canada.
Thomson Reuters disclosed that an unauthorized party obtained files from C-Track, its court case management platform, affecting courts in at least 12 US states, the US Virgin Islands and Canada. The company discovered the activity on June 30 and evidence indicates access ran from March through June; the intrusion method, attacker identity and number of affected people remain unknown. Exposed data may include names, Social Security numbers, driver's license numbers, medical information, dates of birth and health insurance details, including some sealed or redacted court records. Affected individuals are being offered 12 months of free credit monitoring and identity theft protection.
Cyberattack on Manchester Airports Group exposes data of 8.7 million customers
Manchester Airports Group reported a cyberattack exposing booking data of about 8.7 million customers across three English airports.
Manchester Airports Group (MAG), operator of Manchester, London Stansted, and East Midlands airports, disclosed that an unauthorized third party accessed customer data linked to car park, lounge, Fast Track bookings, and Wi-Fi sign-ups. The compromised data includes email addresses, phone numbers, vehicle registrations, and postcodes; no payment or banking details were exposed. The airports handled over 65 million passengers last year, and MAG has suspended its online Manage My Booking service as a precaution. MAG warned affected customers to watch for phishing attempts.