Data breaches
A dark web identity theft service called Nexus began selling digital scans of more than 153 million US and Canadian driver's licenses in the week of August 31, 2026, most of them American. The FBI's New Orleans field office opened an investigation on September 1, and the site went dark hours later.
Investigative journalist Brian Krebs found his own license listed, then asked more than a dozen friends and family for permission to search. All nine he found confirmed traveling on or near the timestamps attached to their images. The common thread was Hertz car rentals, plus a Las Vegas dispensary in one case.
Both point to IDScan.net, a Louisiana identity verification firm that lists Hertz as a client and holds an exclusive agreement with that dispensary chain. IDScan scans IDs with infrared and ultraviolet light, and the Nexus records include infrared and ultraviolet versions of each license.
IDScan.net says it is investigating and has issued no statement. Nexus operators claim a year of continuous exfiltration, and the license count grew by nearly 400,000 in a single day. Licenses for Defense Secretary Pete Hegseth and the FBI's assistant director were among those listed.
NCC Group's Tim Rawlins says organizations should design identity systems assuming that identity evidence will eventually be compromised, and should hold identity vendors to contract terms covering retention, incident notification, and independent assurance.
Source: SecurityWeek
A dark web identity theft service called Nexus began selling digital scans of more than 153 million US and Canadian driver's licenses in the week of August 31, 2026, most of them American. The FBI's New Orleans field office opened an investigation on September 1, and the site went dark hours later.
Investigative journalist Brian Krebs found his own license listed, then asked more than a dozen friends and family for permission to search. All nine he found confirmed traveling on or near the timestamps attached to their images. The common thread was Hertz car rentals, plus a Las Vegas dispensary in one case.
Both point to IDScan.net, a Louisiana identity verification firm that lists Hertz as a client and holds an exclusive agreement with that dispensary chain. IDScan scans IDs with infrared and ultraviolet light, and the Nexus records include infrared and ultraviolet versions of each license.
IDScan.net says it is investigating and has issued no statement. Nexus operators claim a year of continuous exfiltration, and the license count grew by nearly 400,000 in a single day. Licenses for Defense Secretary Pete Hegseth and the FBI's assistant director were among those listed.
NCC Group's Tim Rawlins says organizations should design identity systems assuming that identity evidence will eventually be compromised, and should hold identity vendors to contract terms covering retention, incident notification, and independent assurance.
Source: SecurityWeek
The Minnesota Supreme Court, Court of Appeals, Tax Court, and Court of Administrative Hearings all had user data compromised in a breach at their vendor, Thomson Reuters Court Management Solutions. Attackers were inside the C-Track case management platform from March 1 until June 29, and Thomson Reuters only discovered the intrusion on June 30.
The exposed backup data may include names alongside Social Security numbers, driver's license numbers, dates of birth, medical information and health insurance details. Case documents such as orders and briefs were not affected, and Minnesota courts are operating normally. Chief Justice Natalie Hudson called the compromise deeply troubling.
Minnesota's judicial branch has cut Thomson Reuters' access to court information. Every Minnesota C-Track user has to reset their password — old credentials will lock the account — and affected individuals are being offered 12 months of credit monitoring.
This reaches well past Minnesota. Courts in at least eleven other states, the U.S. Virgin Islands and Ontario, Canada were caught in the same intrusion, which Thomson Reuters says happened inside its own environment rather than the courts' systems. Investigators are still working out what was taken.
Source: CBS News Minnesota
The Minnesota Supreme Court, Court of Appeals, Tax Court, and Court of Administrative Hearings all had user data compromised in a breach at their vendor, Thomson Reuters Court Management Solutions. Attackers were inside the C-Track case management platform from March 1 until June 29, and Thomson Reuters only discovered the intrusion on June 30.
The exposed backup data may include names alongside Social Security numbers, driver's license numbers, dates of birth, medical information and health insurance details. Case documents such as orders and briefs were not affected, and Minnesota courts are operating normally. Chief Justice Natalie Hudson called the compromise deeply troubling.
Minnesota's judicial branch has cut Thomson Reuters' access to court information. Every Minnesota C-Track user has to reset their password — old credentials will lock the account — and affected individuals are being offered 12 months of credit monitoring.
This reaches well past Minnesota. Courts in at least eleven other states, the U.S. Virgin Islands and Ontario, Canada were caught in the same intrusion, which Thomson Reuters says happened inside its own environment rather than the courts' systems. Investigators are still working out what was taken.
Source: CBS News Minnesota
8.7 million people are at risk after hackers breached Manchester Airports Group (MAG) — operator of Manchester, Stansted, and East Midlands airports — and published the stolen data for free. FulcrumSec extorted MAG for an undisclosed sum, failed to get paid, and dumped half a terabyte in response: "every byte of it is pure PII," the gang wrote.
HaveIBeenPwned indexed the dump within a day — names, emails, phone numbers, IP addresses, and 108,000 vehicle plates among them. Unlike most leak sites, this one sits on the open internet rather than the dark web, so anyone can reach it.
Security researcher Kevin Beaumont warned that wealthy or high-profile people face particular risk: the files map where customers have been and where they're going next, including some 190,000 upcoming bookings. MAG says it contacted those travelers separately. Everyone else should expect scammers who know their phone number and car registration.
FulcrumSec says it got in the same way it hit Arup and Novo Nordisk: admin keys to Iterable, MAG's marketing platform, left in the airport websites' JavaScript. "Any of the millions of visitors to the site could have right-clicked 'inspect' and seen the keys," the gang wrote. MAG hasn't confirmed it.
Source: BBC News
8.7 million people are at risk after hackers breached Manchester Airports Group (MAG) — operator of Manchester, Stansted, and East Midlands airports — and published the stolen data for free. FulcrumSec extorted MAG for an undisclosed sum, failed to get paid, and dumped half a terabyte in response: "every byte of it is pure PII," the gang wrote.
HaveIBeenPwned indexed the dump within a day — names, emails, phone numbers, IP addresses, and 108,000 vehicle plates among them. Unlike most leak sites, this one sits on the open internet rather than the dark web, so anyone can reach it.
Security researcher Kevin Beaumont warned that wealthy or high-profile people face particular risk: the files map where customers have been and where they're going next, including some 190,000 upcoming bookings. MAG says it contacted those travelers separately. Everyone else should expect scammers who know their phone number and car registration.
FulcrumSec says it got in the same way it hit Arup and Novo Nordisk: admin keys to Iterable, MAG's marketing platform, left in the airport websites' JavaScript. "Any of the millions of visitors to the site could have right-clicked 'inspect' and seen the keys," the gang wrote. MAG hasn't confirmed it.
Source: BBC News
Chick-fil-A began notifying customers across 11 jurisdictions in late July after a credential-stuffing attack on its loyalty program between June 17 and 19. Thieves used usernames and passwords stolen from a third-party source to break into Chick-fil-A One accounts through the website and app. The company had concluded on July 13 that data may have been accessed.
Data that may have been accessed includes names, email addresses, membership numbers, Mobile Pay numbers, partial payment card digits, gift card balances, and QR codes. Customers who had saved more to their accounts may also have had their birth month and day, phone number, and address accessed.
Chick-fil-A calls it a limited number of accounts and hasn't given a total; filings show 2,182 in Texas and 39 in Massachusetts. It's the second credential-stuffing hit on Chick-fil-A One — an earlier one in 2023 reached more than 71,000 customers.
The company logged out affected users, removed stored payment methods, restored balances, and added rewards as compensation. Customers should reset their passwords and make them unique — reuse is what credential stuffing runs on — then check account activity. A law firm has been investigating a possible class action since early August.
Source: CBS News
Chick-fil-A began notifying customers across 11 jurisdictions in late July after a credential-stuffing attack on its loyalty program between June 17 and 19. Thieves used usernames and passwords stolen from a third-party source to break into Chick-fil-A One accounts through the website and app. The company had concluded on July 13 that data may have been accessed.
Data that may have been accessed includes names, email addresses, membership numbers, Mobile Pay numbers, partial payment card digits, gift card balances, and QR codes. Customers who had saved more to their accounts may also have had their birth month and day, phone number, and address accessed.
Chick-fil-A calls it a limited number of accounts and hasn't given a total; filings show 2,182 in Texas and 39 in Massachusetts. It's the second credential-stuffing hit on Chick-fil-A One — an earlier one in 2023 reached more than 71,000 customers.
The company logged out affected users, removed stored payment methods, restored balances, and added rewards as compensation. Customers should reset their passwords and make them unique — reuse is what credential stuffing runs on — then check account activity. A law firm has been investigating a possible class action since early August.
Source: CBS News
Healthcare giant McKesson confirmed hackers stole customer data after discovering a breach on August 25. Attackers had been pulling data since the 21st. The company, which delivers roughly one-third of North American prescription medicines, said unauthorized access affected its Oncology & Multispecialty and Medical-Surgical business units — though it hasn't disclosed how many people were impacted.
The ShinyHunters extortion group is claiming responsibility, alleging they stole 284 million customer records including medical histories, prescriptions, billing data, and employee files. The group has since conceded that figure counts rows of raw data, not individual people, and that it hasn't finished going through what it took.
They're demanding around $55 million and threatening to publish everything unless McKesson opens payment negotiations by September 1 — that deadline expires today. McKesson hasn't engaged, says its services remain operational, and still hasn't determined how much data was taken. None of ShinyHunters' claims have been verified.
Source: SecurityWeek
Healthcare giant McKesson confirmed hackers stole customer data after discovering a breach on August 25. Attackers had been pulling data since the 21st. The company, which delivers roughly one-third of North American prescription medicines, said unauthorized access affected its Oncology & Multispecialty and Medical-Surgical business units — though it hasn't disclosed how many people were impacted.
The ShinyHunters extortion group is claiming responsibility, alleging they stole 284 million customer records including medical histories, prescriptions, billing data, and employee files. The group has since conceded that figure counts rows of raw data, not individual people, and that it hasn't finished going through what it took.
They're demanding around $55 million and threatening to publish everything unless McKesson opens payment negotiations by September 1 — that deadline expires today. McKesson hasn't engaged, says its services remain operational, and still hasn't determined how much data was taken. None of ShinyHunters' claims have been verified.
Source: SecurityWeek
Manchester Airports Group (MAG), which operates Manchester, East Midlands, and London Stansted, has confirmed a cyberattack that exposed the personal data of around 8.7 million customers. Hackers took contact details, vehicle registrations and postcodes over the weekend of August 22–23, then demanded a ransom for the data's return — which MAG refused to pay.
MAG only became aware on Tuesday, August 25, and says it cut off further access and notified affected customers. For the majority, the data was limited to the email address given when signing up to airport WiFi; the more detailed records came from car park, lounge, and fast-track bookings.
The hacked system didn't hold bank or payment card details, MAG says, and at no point was passenger safety or aviation security compromised. The group says it knows the hackers' identity and has informed the relevant authorities.
The Information Commissioner's Office has received MAG's breach report and says it is assessing the information provided. Affected customers should watch for suspicious emails, texts or calls, and avoid opening unknown attachments.
Source: BBC News
Manchester Airports Group (MAG), which operates Manchester, East Midlands, and London Stansted, has confirmed a cyberattack that exposed the personal data of around 8.7 million customers. Hackers took contact details, vehicle registrations and postcodes over the weekend of August 22–23, then demanded a ransom for the data's return — which MAG refused to pay.
MAG only became aware on Tuesday, August 25, and says it cut off further access and notified affected customers. For the majority, the data was limited to the email address given when signing up to airport WiFi; the more detailed records came from car park, lounge, and fast-track bookings.
The hacked system didn't hold bank or payment card details, MAG says, and at no point was passenger safety or aviation security compromised. The group says it knows the hackers' identity and has informed the relevant authorities.
The Information Commissioner's Office has received MAG's breach report and says it is assessing the information provided. Affected customers should watch for suspicious emails, texts or calls, and avoid opening unknown attachments.
Source: BBC News
Australian authorities arrested two Western Australia men on Wednesday, August 26, over their alleged roles in TeamPCP, the cybercrime group that injected credential-stealing code into Aqua Security's Trivy scanner, Checkmarx KICS and LiteLLM in March. The AFP says that code potentially compromised more than 1,000 organizations worldwide.
Police didn't name the pair; Australian media identified them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. Between them they face 14 charges, including four counts each of unauthorized modification of data with intent to commit a serious offence. Only Thomson faces a proceeds-of-crime count over $100,000 and a password-refusal charge.
The AFP estimates the code enabled theft of more than 500,000 credentials and at least 300GB of data, with global cleanup costs in the hundreds of millions. CERT-EU tied the European Commission's cloud breach to the poisoned Trivy release. Flare assesses with high confidence that Thomson led TeamPCP.
Both men appeared in Perth Magistrates Court on Thursday. Thomson withdrew a bail application after the magistrate signalled she would refuse it, and both remain in custody until September 18.
Source: CyberScoop
Australian authorities arrested two Western Australia men on Wednesday, August 26, over their alleged roles in TeamPCP, the cybercrime group that injected credential-stealing code into Aqua Security's Trivy scanner, Checkmarx KICS and LiteLLM in March. The AFP says that code potentially compromised more than 1,000 organizations worldwide.
Police didn't name the pair; Australian media identified them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. Between them they face 14 charges, including four counts each of unauthorized modification of data with intent to commit a serious offence. Only Thomson faces a proceeds-of-crime count over $100,000 and a password-refusal charge.
The AFP estimates the code enabled theft of more than 500,000 credentials and at least 300GB of data, with global cleanup costs in the hundreds of millions. CERT-EU tied the European Commission's cloud breach to the poisoned Trivy release. Flare assesses with high confidence that Thomson led TeamPCP.
Both men appeared in Perth Magistrates Court on Thursday. Thomson withdrew a bail application after the magistrate signalled she would refuse it, and both remain in custody until September 18.
Source: CyberScoop
George House Trust, a Manchester-based HIV charity, has warned users that their sensitive health data may have been stolen by hackers. The breach, which occurred at the end of July, exposed personal details including addresses, phone numbers, and case notes about users' engagement with the charity.
The incident stems from a cyberattack on Beacon, a tech company whose database system is used by 1.5K+ UK charities. George House Trust was notified on 3 August but waited three weeks before alerting users. So far, no stolen data appears to have been misused. Investigations are ongoing.
Source: BBC News
George House Trust, a Manchester-based HIV charity, has warned users that their sensitive health data may have been stolen by hackers. The breach, which occurred at the end of July, exposed personal details including addresses, phone numbers, and case notes about users' engagement with the charity.
The incident stems from a cyberattack on Beacon, a tech company whose database system is used by 1.5K+ UK charities. George House Trust was notified on 3 August but waited three weeks before alerting users. So far, no stolen data appears to have been misused. Investigations are ongoing.
Source: BBC News
A cyberattack hit Ceva Logistics on July 29, knocking out eight European warehouses and halting shipments. The French-headquartered logistics giant told corporate client Bol about the intrusion on August 1 — but the notices that reached consumers came from the retailers themselves, not from Ceva.
Several major organizations confirmed impact, including Dutch retailers Bol and De Bijenkorf, ING, Ace & Tate, Amsterdam's Ajax football club, and game company Valve. Exposed data includes names, addresses, phone numbers, emails and order details.
De Bijenkorf said no payment details, IBANs, card data, usernames or passwords were involved; Ceva never held Steam payment credentials either. Valve says Ceva keeps order records up to 90 days, and has warned customers to expect fake emails, texts, and calls about their hardware orders.
Who's behind the attack remains unknown. Ceva has not publicly disclosed the incident, responded to press enquiries, or said how the intruders got in or how many people are affected.
Source: SecurityWeek
A cyberattack hit Ceva Logistics on July 29, knocking out eight European warehouses and halting shipments. The French-headquartered logistics giant told corporate client Bol about the intrusion on August 1 — but the notices that reached consumers came from the retailers themselves, not from Ceva.
Several major organizations confirmed impact, including Dutch retailers Bol and De Bijenkorf, ING, Ace & Tate, Amsterdam's Ajax football club, and game company Valve. Exposed data includes names, addresses, phone numbers, emails and order details.
De Bijenkorf said no payment details, IBANs, card data, usernames or passwords were involved; Ceva never held Steam payment credentials either. Valve says Ceva keeps order records up to 90 days, and has warned customers to expect fake emails, texts, and calls about their hardware orders.
Who's behind the attack remains unknown. Ceva has not publicly disclosed the incident, responded to press enquiries, or said how the intruders got in or how many people are affected.
Source: SecurityWeek
Florida's Department of Health is reaching out to people affected by a June 26 cyberattack that exposed a wide range of sensitive personal data. We're talking names, Social Security numbers, banking details, medical history, medication and prescription information, military identification numbers, Nexus numbers, passwords, passport numbers — the works. The department has started mailing letters to those impacted with specifics on what was accessed.
To help, they've partnered with Kroll, an identity-monitoring firm, to provide free credit monitoring services. Law enforcement and cybersecurity experts are actively investigating. If you're a Florida Health Department client and haven't received a letter yet, it's worth keeping a close eye on your accounts.
Source: CBS News Miami
Florida's Department of Health is reaching out to people affected by a June 26 cyberattack that exposed a wide range of sensitive personal data. We're talking names, Social Security numbers, banking details, medical history, medication and prescription information, military identification numbers, Nexus numbers, passwords, passport numbers — the works. The department has started mailing letters to those impacted with specifics on what was accessed.
To help, they've partnered with Kroll, an identity-monitoring firm, to provide free credit monitoring services. Law enforcement and cybersecurity experts are actively investigating. If you're a Florida Health Department client and haven't received a letter yet, it's worth keeping a close eye on your accounts.
Source: CBS News Miami