Data Breach Roundup (Sep 18 - 24, 2026)
Gyazo server flaw exploited to steal 23.6 million user records
Gyazo is a cloud-based screenshot, screen-recording, and image-sharing platform popular in the gaming community. The incident occurred on September 11 and impacted names/nicknames, email addresses, hashed passwords, user & device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile details, subscription information, billing status, and usage statistics. It also exposed anonymous account records and 490 million image metadata records, mostly from images uploaded prior to January 19.

BigCommerce alerts merchants of data breach linked to Ribon apps
BigCommerce is a third-party Software-as-a-Service ecommerce platform. They suffered a "credential compromise" on September 17. The breach impacted Master of Malt and several other unnamed retailers. Master of Malt said shopper full names, email addresses, phone numbers, and shipping postal addresses were impacted. Little else is known at this time.

‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees
ShinyHunters is claiming they have agent names, home addresses, phone numbers, date of birth, and information on their spouses for all FBI employees and applicants. BleepingComputer reports that the attackers breached Oracle PeopleSoft using a zero-day then moved into AWS and stole between 2-3TB of data.

Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Miljödata is a Swedish software company that develops and provides work environment and HR management systems used by 80% of Sweden’s municipal systems. They suffered a cyberattack in August 2025 which disrupted services in over 200 regions and impacted residents' sensitive data including personal identity numbers, contact information, sickness absence, rehabilitation, and school incidents involving underage individuals.

Community Discussion