Manchester Airports Group breached, millions of customers’ data stolen
Manchester Airports Group confirmed attackers stole customer booking and WiFi signup data affecting about 8.7 million customers across three UK airports.
Manchester Airports Group (MAG) confirmed an unauthorized third party obtained customer data tied to car park, lounge and Fast Track bookings and WiFi sign-ups at Manchester, Stansted and East Midlands airports. Stolen data includes email addresses, phone numbers, vehicle registrations and postcodes; no payment or banking details were held in the affected systems. UK media reported roughly 8.7 million customers affected. The Manage My Booking portal was disabled as a precaution, authorities were informed, and airport operations were not disrupted.
Cybercrooks jet off with Manchester Airports Group customer data
Manchester Airports Group says cybercriminals took customer data affecting an estimated 8.7 million customers at the UK's largest airport operator.
The Register reports that Manchester Airports Group, the UK's largest airport operator, believes approximately 8.7 million customers were affected by a cyber incident. The attackers are described as cybercriminals, with data tied to bookings and Wi-Fi registrations at Manchester, Stansted and East Midlands airports. This report adds a scale estimate to the group's breach disclosure.
Revolut confirms customer data breach through fake government requests
Revolut disclosed customer identity data, including passports and possibly selfies, to an attacker using a legitimate government email domain.
Attackers impersonating a government agency used a legitimate agency email domain to submit fraudulent information requests, prompting Revolut to disclose customer identity and contact data to an unauthorized third party. Exposed data included birth dates, postal and email addresses, phone numbers, passport and driver's license copies, and possibly verification selfies, account statements, and transaction histories. Revolut said a limited number of customers were affected, blocked the email address, and notified the agency, law enforcement, and regulators, adding that systems and customer funds were unaffected. Security researcher ZachXBT reported the scam appeared to target high net worth users of the fintech, which serves over 80 million customers.
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Trezor disclosed the ShipMonk breach exposed data of 67,000 additional US customers, reportedly by ShinyHunters exploiting a Metabase zero-day SQL injection, CVE-2026-72898.
Trezor disclosed that a breach at shipping provider ShipMonk exposed names, email addresses, phone numbers, shipping addresses, and order numbers of 67,000 additional US customers, with orders dating November 2019 to August 2021 despite written assurances the data had been deleted. This adds to the 13,689 customers previously disclosed after ShipMonk informed Trezor of unauthorized access on August 10, 2026. According to Holborn, the ShinyHunters extortion gang is behind the breach, which began with zero-day exploitation of CVE-2026-72898 (CVSS 10.0), a critical SQL injection flaw in Metaboobase analytics software Metabase. Trezor says hardware wallet security is unaffected but warns customers to watch for phishing and social engineering; ShipMonk has not publicly acknowledged the incident.
Electronic health record company says customer data stolen in breach
Veradigm disclosed that attackers used stolen vendor credentials via an API to steal patient data including Social Security numbers, as the Gentlemen ransomware gang claims 3.5 million patients' records.
Electronic health records company Veradigm filed an 8-K with the SEC stating that an unauthorized party obtained credentials from a vendor's environment and used them to access a Veradigm API, downloading patients' personal data including Social Security numbers; no clinical or medical data was involved. The Gentlemen ransomware gang added Veradigm to its leak site, claiming theft of 3.5 million patients' health records. Access was limited to the specific API interface, with no operational disruption. Veradigm was previously hit by SamSam ransomware in 2019 and disclosed a December 2024 breach affecting 2,672,036 people.
CEVA Logistics Cyberattack Disrupts European Warehouses and Shipments
Cyberattack on CEVA Logistics disrupted eight European warehouses and exposed customer data of clients including Valve, Ajax, and De Bijenkorf.
CEVA Logistics, part of CMA CGM Group, suffered a July 29 cyberattack that disrupted eight European warehouses and halted shipments of stored goods. Customer data linked to Valve, Ajax, and Dutch retailer De Bijenkorf was exposed, potentially including names, contact details, and online order information; Valve said payment details and passwords were not accessed. No ransomware group has claimed responsibility and the company has not disclosed technical details. A database containing customer lists, shipping records, and banking details was reportedly later offered for sale on a dark web marketplace.
IDScan confirms breach after hackers offer 153 million driver’s license scans for sale
IDScan confirmed hackers accessed customer data in its cloud after scans of roughly 153 million driver's licenses surfaced for sale on a dark web marketplace.
IDScan.net published a breach notice on September 4, after learning around September 1 that an unauthorized third party may have accessed or copied customer information in its cloud platform, potentially including full names and government-issued ID numbers. KrebsOnSecurity tied the incident to Nexus, a Russia-linked dark web marketplace selling access to over 153 million US and Canadian driver's license scans, plus 10 million ID cards, more than 3 million travel documents, and at least 579,000 medical cards. The company did not disclose how many customers were affected, is offering free credit monitoring, faces multiple lawsuits, and the FBI has opened an inquiry. IDScan's government ID authentication is widely used by banks, cannabis retailers, and gun stores.
Manchester Airports Group Hit by Cyber Incident
Manchester Airports Group disclosed that an unauthorized third party accessed customer data from bookings and airport Wi-Fi registrations.
Manchester Airports Group, which operates Manchester, Stansted and East Midlands airports, reported a cyber incident in which an unauthorized third party accessed customer data. Affected data is linked to bookings and airport Wi-Fi registrations. The number of affected customers was not stated in this report.
Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack
Pharmaceutical giant McKesson disclosed a cyberattack on a third-party application that exfiltrated customer data, claimed by ShinyHunters.
McKesson reported a cybersecurity incident involving an unnamed third-party application, with attackers exfiltrating data tied to its oncology and surgical business units. The company filed with the SEC, offered credit monitoring, and said it had received reasonable assurance the attackers were no longer inside its systems. The ShinyHunters group claimed responsibility and threatened leaks; McKesson reported $106 billion in revenue last quarter and distributes about one-third of North American prescriptions.
Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe
Cyberattack on Ceva Logistics disrupted eight European warehouses, delaying shipments for Bol, De Bijenkorf, Ajax and exposing Steam hardware buyers' data.
A cyberattack on Ceva Logistics disrupted operations at eight European warehouses, delaying shipments for Bol, De Bijenkorf, Ace & Tate, Ajax and Steam hardware customers. Attackers accessed two Ceva systems processing Bol orders, potentially exposing names, addresses, phone numbers, email addresses and order details. Valve began notifying European Steam customers whose hardware shipping data may have been compromised and is contacting data protection authorities. Ceva, with about 110,000 employees and over 1,700 facilities, has not disclosed the attackers or whether ransomware was involved.