BigCommerce confirmed that credentials for third-party Ribon and Ribon 1.5 apps, made by Fastr's Be A Part Of, were stolen and used to inject malicious scripts into a small number of merchant storefronts between September 13 and 17. UK retailer Master of Malt was among those affected, with attackers accessing customer names, emails, phone numbers, and shipping addresses, though passwords and payment data were not exposed. BigCommerce says its core platform and systems remained secure, and it disabled the compromised apps upon discovery.
South Korea's Personal Information Protection Commission has enacted rules allowing fines of up to 10% of a company's annual revenue for major data leaks caused by intent or gross negligence, up from the previous 3% cap. The new rules, effective Friday, apply when 10 million or more people's data is exposed, and also require firms to notify users within 72 hours even if a breach is only suspected. The heightened penalty targets repeat offenders within three years or firms that ignore corrective orders and are subsequently breached.
Helpfeel-operated screenshot service Gyazo confirmed that attackers exploited a server flaw on September 11, 2026 to access its database and steal roughly 23.62 million user records. The company detected the intrusion the following day, patched the vulnerability, and has taken the platform offline for maintenance while investigating. Exposed data varies by account but can include names, emails, password hashes, session and device IDs, SSO tokens, billing details, and usage statistics, alongside 490 million image metadata records.
Spain's Data Protection Agency (AEPD) disclosed that an organization reported a breach in which an attacker used a mainstream language model to locate weak credentials and exploit an application flaw. The AI agent reportedly enabled the attacker to access corporate invoices and modify personal data records, though the organization and hacker remain unnamed.
Hackers physically removed a Flock Safety license plate reader from a roadway, extracted an encryption key from its storage, and shared the recovered files with 404 Media and WIRED. The data showed the device's software identifies not just vehicles and plates but also people, bicycles, and even small details like bumper stickers, generating over a million images in just weeks of logs.
Spain's Data Protection Agency (AEPD) has received its first notification of a breach allegedly executed by an autonomous AI agent built on a large language model. According to the report, the agent found system vulnerabilities, logged in, probed connected applications, then altered personal data and accessed financial records. The AEPD has not yet verified the claims but says the case demonstrates that AI-driven breaches have moved from theory to practice.
A group of hackers physically removed a Flock Safety license-plate camera, copied its internal storage, and recovered an encryption key that unlocked thousands of stored vehicle images. They shared the extracted files with 404 Media and WIRED, and separately with the transparency group Distributed Denial of Secrets, along with details of how they pulled off the extraction so others could replicate it.
IBM's Cost of a Data Breach Report 2025 puts the average total cost of a ransomware incident at $5.08 million once downtime, remediation, legal work and business disruption are counted, while Verizon's 2026 DBIR pegs the median ransom payment at just $139,875. Datto's State of BCDR Report 2025 adds that while over 60% of organizations expect to recover within a day, only 35% actually do, and attackers increasingly target backup systems, forcing costly forensic and incident-response work when recovery options are compromised.
Revolut, valued as Europe's most valuable startup, disclosed customer information to an individual who fraudulently claimed to represent a government agency. Hundreds of accounts were affected by the breach, which stemmed from the bank's own verification failure rather than a hack of its systems.
A year-end review of 2026's major hacks highlights an unresolved controversy over the Department of Government Efficiency's access to Social Security Administration data. Ongoing federal lawsuits and a whistleblower's claims allege DOGE staff uploaded a live copy of the Social Security database to an unsecured third-party server, potentially exposing sensitive personal information tied to most living Americans. The broader roundup also notes a year marked by ransomware, nation-state attacks on infrastructure, and data weaponization by governments.
CenterPoint Energy has confirmed in an SEC filing that an unauthorized party accessed customer personal information through one of its external-facing systems. The disclosure follows claims from a hacker who says they exfiltrated 7.49 million records—including names, addresses, account numbers, billing details and partial Social Security numbers—by exploiting an unprotected public API lacking rate limiting or firewall defenses.
Revolut disclosed that it inadvertently sent personal and financial data of some customers to a threat actor who impersonated a government agency using an authenticated domain. The leaked data reportedly includes identity documents, selfies, account statements, IBAN numbers, and transaction histories, including Bitcoin transactions. Revolut says the breach affects a limited but undisclosed number of accounts and that customer funds remain unaffected.