Skip to content
Tech News
clear
Topics: Today This Week This Month This Year

CenterPoint Energy confirms data breach after hacker leaks 7.49 million records

CenterPoint Energy has confirmed in an SEC filing that an unauthorized party accessed customer personal information through one of its external-facing systems. The disclosure follows claims from a hacker who says they exfiltrated 7.49 million records—including names, addresses, account numbers, billing details and partial Social Security numbers—by exploiting an unprotected public API lacking rate limiting or firewall defenses.

Revolut exposes customer passports and financial data via fake government request

Revolut disclosed that it inadvertently sent personal and financial data of some customers to a threat actor who impersonated a government agency using an authenticated domain. The leaked data reportedly includes identity documents, selfies, account statements, IBAN numbers, and transaction histories, including Bitcoin transactions. Revolut says the breach affects a limited but undisclosed number of accounts and that customer funds remain unaffected.

Misconfigured Vietnam-linked APIS database exposed 220 million traveler records

Security researchers at Kinryu Labs found an unsecured Elasticsearch cluster in Viettel-assigned IP space in Hanoi containing over 220 million passenger and crew records dating from 2017 to 2026. The exposed data included passport numbers, nationalities, dates of birth, flight details, seat assignments and baggage information, accessible due to a chain of misconfigurations and default credentials. The database was secured after being reported, though it remains unknown whether the data was accessed or copied before that point.

Revolut Discloses Customer Data Breach via Spoofed Government Email

Revolut confirmed it handed over sensitive customer data after being deceived by fraudulent requests sent from what appeared to be a legitimate government agency email domain. Exposed information reportedly included names, birth dates, addresses, phone numbers, ID documents like passports and driver's licenses, and possibly verification selfies and financial statements. The company says a limited number of customers were affected and has since blocked the malicious email address.

Revolut Exposes Customer Data After Fake Government Email Scam

Revolut confirmed it handed over sensitive customer information after receiving fraudulent data requests sent from what appeared to be a legitimate government agency email domain. The exposed data reportedly included names, birth dates, addresses, phone numbers, ID documents, and possibly verification selfies and transaction histories. The company says only a limited number of customers were affected and that it has since blocked the fraudulent email address and alerted authorities.

FLHSMV: DAVID driver database breached via stolen Plant City police credentials

Florida's Department of Highway Safety and Motor Vehicles confirmed the ShinyHunters extortion group breached its DAVID driver database on September 4, 2026, after the gang claimed to have stolen over 200,000 driver records. FLHSMV said the intruder used login credentials from a single Plant City Police Department account that had been improperly saved on the employee's personal device, contradicting ShinyHunters' claim that it exploited a password-reset flaw across multiple accounts.

Trezor customers hit by phishing wave after Brevo email vendor breach

Trezor disclosed that hackers who compromised 138 accounts at email marketing provider Brevo used the access to send roughly 347,000 phishing emails to its customers. The messages, disguised as security alerts, directed recipients to a fake app designed to steal their wallet backup passwords. Trezor says its own products and account systems were not breached, but the stolen credentials could let attackers drain victims' crypto holdings.

Trezor confirms 347,000 emails exposed via Brevo breach, 2,500 users phished

Trezor disclosed that a breach at its third-party email provider Brevo let attackers send fake security alerts to its opt-in newsletter subscribers, reaching roughly 347,000 email addresses. The fraudulent messages warned of a fake microcontroller vulnerability and pushed recipients to a malicious app requesting wallet backup phrases; Trezor says 2,500 people clicked the link before it disabled the domain within 20 minutes.

IDScan breach exposes 153 million driver's licenses, hackers ran year-long data theft via Nexus

ID verification company IDScan disclosed that hackers accessed its systems without authorization, a breach later linked to a criminal marketplace called Nexus selling scans of over 170 million identity documents. Security researcher Brian Krebs verified the stolen trove includes 153 million driver's licenses, 10 million ID cards, 3 million passports and travel documents, and hundreds of thousands of medical cards, mostly belonging to US residents with some Canadian records included. The attackers claimed to have quietly siphoned data from IDScan's systems for more than a year before being detected.

Surfshark confirms breach of internal test and proxy servers, no user data affected

Surfshark disclosed that hackers gained access to an internal engineering test server after a misconfiguration left it exposed to the internet, along with a separate proxy server used for content-accessibility optimization. The company says the exposed systems contained build credentials, code history and system binaries, but no user identities, IP addresses, encryption keys or browsing traffic were compromised. Suspicious activity was spotted on August 31, contained by September 2, and remediation finished three days later.

IDScan confirms breach exposing 150 million driver's licenses

IDScan, a Louisiana-based identity verification firm used by venues and dispensaries, confirmed hackers stole driver's licenses and other government ID data from its cloud systems. The admission follows a report by cybersecurity journalist Brian Krebs that a dark web site allowed searches of over 150 million U.S. and Canadian residents' license records, including photos and data belonging to high-profile figures like Defense Secretary Pete Hegseth.

Today's top topics: openai samsung smart glasses android authority gemini adobe premiere anthropic data centers galaxy s27 ultra battersea power station
View all today's topics →