UpGuard found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens, with a very small subset appearing to include credit card data. Supabase is an open-source PostgreSQL development platform, popular with developers using AI tools, which now account for more than 60 percent of newly created databases. UpGuard analyzed about 300,000 domains showing Supabase use and inferred exposed data types from table schemas. More than half of the exposed databases held PII, with a smaller subset exposing passwords and tokens. One US valet service alone exposed over 100,000 customer records, showing how missing access controls turn convenient backends into open data stores.
Cryptocurrency exchange Bitget said the attacker who stole about 388 million dollars gained access through a vulnerability in a third-party security product the exchange used. The attacker exploited the flaw to obtain high-level internal credentials, then on September 24 used them to reach an internal management system and insert fraudulent withdrawal commands into wallet backend services, where they were treated as legitimate. The stolen funds came from Bitget's hot and warm wallets, while its offline cold wallets were unaffected. CEO Gracy Chen described the incident publicly, confirming the earlier statement that a critical wallet backend system had been compromised and used to spoof transaction data and trigger approvals.
Texas utility CenterPoint Energy confirmed that an unauthorized party obtained customer personal information through an external-facing system. A threat actor claimed on a cybercrime forum to have pulled about 7.49 million records, including names, addresses, account and billing details, and partial Social Security numbers, through a company API that lacked authentication, rate limiting, and web-application-firewall protection. CenterPoint confirmed the incident in a regulatory filing but not the record count, and said energy services were unaffected. It is a textbook example of an exposed API being scraped at scale: without authentication and throttling, a public endpoint hands attackers a bulk export of customer data. The investigation is ongoing.
Fintech Revolut disclosed that it released sensitive customer data to attackers who sent a fraudulent information request from an email account operating inside a real government agency's domain. Because the message passed standard email-authentication checks, Revolut treated it as a genuine legal or government request and complied. The exposed data for a limited number of users included passport or driver's license copies, verification selfies, full identity and contact details, and complete transaction histories including Bitcoin activity. It was not a breach of Revolut's systems but an abuse of the trusted legal-request process. The combined identity and financial data enables convincing impersonation, SIM-swapping, and targeted attacks on cryptocurrency holders.
Identity-verification company IDScan confirmed that attackers accessed customer data in its cloud, behind a dark-web marketplace offering scans of more than 153 million US and Canadian driver's licenses, plus names and government-ID numbers. IDScan authenticates government IDs for businesses ranging from banks to car-rental agencies to cannabis and gun retailers, which makes it an aggregator of everyone's identity documents and a single point of mass failure. Investigative journalist Brian Krebs traced the marketplace back to IDScan by matching document scans to occasions when IDs were presented. The FBI is investigating and lawsuits have been filed. Because these are scanned government IDs, victims cannot simply rotate a leaked driver's license.
VPN provider Surfshark disclosed that attackers accessed an internal engineering test server that a configuration error had left reachable from the internet, along with a proxy server used for content optimization. Surfshark says the exposure was limited to a non-production environment and included service configurations, build-related credentials, system binaries, and portions of code history, but did not reach customer data, VPN traffic, encryption keys, or production systems. The company detected the activity on August 31, contained it by September 2, rotated credentials, revoked tokens, and completed remediation within days. It is a reminder that misconfigured internet-exposed test environments remain a common and avoidable breach path, even at security-focused companies.
AdaptHealth, a US network of more than 680 medical-equipment facilities, confirmed that a breach attributed to the ShinyHunters group exposed the personal, health, and insurance information of about 4.1 million people. The attackers got in by socially engineering a third-party contractor's privileged account, then reached AdaptHealth's cloud business applications, patient-management systems, and electronic health record portals, and stole a password file tied to insurance billing. It fits ShinyHunters' pattern of tricking a person into handing over access to connected cloud services, and it is the latest in a wave of large healthcare breaches this year alongside Aesto, CareCloud, and McKesson. Social security and financial data were reportedly not taken.
The extortion group ShinyHunters claims it breached Florida's DAVID system, an internal driver and vehicle database used by law enforcement and state officials, and stole more than 200,000 records. According to the group, a password-reset flaw let it take over several internal accounts, including those of motor-vehicle employees and, notably, an FBI agent, which it then used to pull driver files, photos, and signatures by cycling through record IDs. It posted a sample it says is a public figure's license as proof and set a leak deadline. Florida's agency has not confirmed the breach, and the claim is unverified, but the group is reportedly probing other states' motor-vehicle systems the same way.
Researchers found an exposed database holding more than 220 million airline passenger and crew records, including passport numbers and full flight itineraries, left reachable online. The data came from an Advance Passenger Information System, the kind airlines use to send traveler identity and passport details to border authorities, and it covered anyone who flew to, from, or through Vietnam between 2017 and 2026. Exposed fields included names, dates of birth, nationalities, passport numbers with issuing countries, and flight, seat, and baggage details. Researchers reached it by chaining misconfigurations and default credentials, and it was later secured, though whether the data was copied first is unknown because no access logs existed.
Thomson Reuters disclosed that attackers obtained files from C-Track, a court case-management platform sold by its West Publishing unit, affecting courts across eleven US states, the US Virgin Islands, and Ontario, Canada. The intrusion happened in March and was not discovered until the end of June. Exposed records may include names, Social Security numbers, driver's license numbers, dates of birth, and medical and insurance information, and at some courts confidential, redacted, or sealed court information may also have been taken. The stolen data came from database backups that courts had supplied to the vendor for troubleshooting. How the attackers got in, and why they went unnoticed for months, remains unanswered.