The ShinyHunters extortion group says it broke into Florida's DAVID driver database used by law enforcement, allegedly exploiting a password-reset weakness to hijack multiple accounts, including one belonging to an FBI agent. The hackers claim to have exfiltrated over 200,000 driver records and posted Jeffrey Epstein's DMV file—complete with his address, Social Security number, and vehicle history—as proof, while listing the Florida Highway Safety and Motor Vehicles agency on their leak site to pressure payment.
Mathspace, an online maths learning platform used in thousands of schools, revealed that hackers breached its self-hosted Metabase reporting tool and stole personal data on students, parents, guardians and staff. The company said attackers first gained access on August 10, extracted data on August 27, and the breach was confirmed on September 3, affecting 1,079,819 people in Australia and New Zealand. Mathspace stated that passwords, academic records and authentication credentials were not compromised.
Trezor has revised the scope of its August data breach, now saying 81,000 customers were affected instead of the roughly 14,000 first reported. The increase stems from logistics partner ShipMonk failing to delete older records as its contract required, exposing details of 67,000 additional U.S. customers who ordered between November 2019 and August 2021.
IDScan, an identity verification firm used by rental car companies, retailers and other businesses, faces multiple lawsuits after a dark-web service called Nexus allegedly offered access to over 153 million U.S. and Canadian driver's licenses along with millions of other ID documents. Journalist Brian Krebs traced the leaked data back to IDScan, and the FBI's New Orleans office has reportedly opened an investigation. IDScan has not confirmed a breach occurred or commented publicly on the allegations.
A dark web identity-theft service is selling scans of more than 153 million U.S. and Canadian driver's licenses, apparently sourced from a Louisiana-based identity verification company that supplies age- and ID-checking services. Investigator Brian Krebs found the site was still adding hundreds of thousands of new records daily, including 400,000 added the day the breach was exposed, before the service was finally taken offline.
A trove of roughly 153 million scanned driver's licenses, reportedly stolen from an identity verification company, has surfaced for sale online. The leak underscores how centralized repositories of scanned IDs, built to confirm users' identities, have themselves become prime targets for hackers.
A dark web marketplace called Nexus emerged this week claiming to sell searchable access to over 150 million U.S. and Canadian driver's licenses and passports, with roughly half a million new records added daily. Security journalist Brian Krebs and researcher Zach Edwards traced the likely source to IDScan, a Louisiana-based identity verification firm used by major consumer brands to check tens of millions of IDs monthly. Both researchers confirmed their own personal documents appeared in the database, and Defense Secretary Pete Hegseth's photo was also reportedly found among the listings.
A criminal hacking group has published personal data belonging to nearly 8.7 million customers of Manchester, London Stansted and East Midlands airports after breaching Manchester Airports Group's systems. The attackers had demanded a ransom, which MAG did not pay, and have now released roughly half a terabyte of stolen information—including contact details, vehicle registrations and postcodes—free of charge to other criminals via their own website.
Aesto LLC, which runs Aesto Health's data migration and archiving service for healthcare providers, revealed that an unauthorized actor accessed its AWS infrastructure between December 2 and 18, 2025. The breach, confirmed internally on May 26 after forensic review, exposed sensitive records for over 9.5 million people including Social Security numbers, driver's license numbers, and medical information tied to 29 healthcare clients such as VillageMD and Together Women's Health.
Dropbox notified users that attackers gained unauthorized access to their accounts between August 4 and 21, 2026, though the company says no files were confirmed viewed or downloaded. The breach stemmed from a weakness in Lenovo's identity verification process, which let attackers register Lenovo IDs tied to victims' email addresses without owning those inboxes, then use those IDs to log into linked Dropbox accounts.
Novocure disclosed to the SEC that attackers gained unauthorized access to its systems in mid-August, exposing over 1,400 U.S. patient ID records without names attached. Fewer than 50 patients in the western U.S. had identifying information and healthcare provider contact details compromised, and an unspecified number of employees also had contact information exposed. The company says its treatment devices and operations remain unaffected and it is assessing notification obligations.
Brave has rolled out a new 'email aliases' tool in its browser that lets users generate disposable email addresses which forward messages to their real inbox. Users can create up to five free aliases by verifying their main email through Brave's settings, then right-clicking any email field on a website to generate and insert an alias.