The week in breach news

User data was exposed across regions and sectors this week, with more than 200 million people potentially caught up in a wave of major breaches. The FBI is investigating what could be one of the largest exposures of government-issued identity documents ever recorded in North America, with over 170 million people potentially affected. Elsewhere, more than 32 million Condé Nast users have had their data exposed, learning provider Mathspace confirmed a breach affecting over a million people across Australia and New Zealand and a cyberattack at Baylor Genetics has left the protected health data of nearly three million people compromised.

The week in breach news

North America

U.S. and Canada citizens

Industry: Government & Public SectorExploit: Hacking

The FBI announced on September 2 that it is investigating a possible data breach that may have exposed more than 153 million driver's licenses belonging to people in the U.S. and Canada.

A dark web site called Nexus claims to be selling millions of digital scans of identity documents belonging to more than 170 million people across North America. The stolen data allegedly includes more than 153 million driver's licenses, over 10 million identification cards and more than three million travel documents and international IDs. The FBI confirmed it is looking into the incident but declined to comment further given the ongoing nature of the investigation.

If the claims are accurate, this could rank among the largest exposures of government-issued identity documents ever recorded in North America, putting tens of millions of people at risk of identity theft and fraud.

Source

How it could affect your business

A data exposure of this scale can have far-reaching repercussions, as cybercriminals can use this data for targeted phishing scams, identity fraud and account takeovers. Businesses should remind users to verify the source of any unexpected emails or messages before clicking links or sharing information and to be especially cautious of communications that reference personal details like addresses or ID numbers. Encouraging users to monitor their accounts for suspicious activity and report anything unusual can also help catch fraud attempts early before they cause lasting damage.

North America

Condé Nast

Industry: Media, Sports & EntertainmentExploit: Hacking

In another massive breach of user data, a database said to contain 32.8 million Condé Nast user records is reportedly being offered for $15,000 on a Russian-language cybercrime forum.

Condé Nast is an American mass media company with a widely popular publishing portfolio that includes Vogue, The New Yorker, GQ, Glamour, WIRED and Vanity Fair. The database, which reportedly went on sale on September 7, 2026, is claimed to contain 32,815,767 user records, including email addresses, names, postal addresses, gender, dates of birth and phone numbers. The listing does not include passwords, password hashes, usernames or payment card data.

Condé Nast has not publicly confirmed the breach or commented on the sale listing at this time.

Source

How it could affect your business

When stolen data makes its way onto cybercrime forums, it can be bought and exploited long before the affected organization even confirms a breach. Dark web monitoring gives businesses an early warning when customer or employee data surfaces in these spaces, allowing them to act before that data is used for fraud or targeted attacks. Without it, organizations are often the last to know their data is already in circulation.

Australia & New Zealand

Mathspace

Industry: EducationExploit: Hacking

The ANZ region also found itself caught up in this wave of massive breaches of user data, with learning provider Mathspace confirming that more than a million people, including students, school staff and parents, have been affected by a recent data breach.

Mathspace confirmed that unauthorised parties accessed an internal reporting system between August 10 and August 27 by exploiting a security vulnerability in its self-hosted software installation. A security patch that could have prevented the breach had not been installed during the affected period. The exported data includes user IDs, usernames, first and last names, email addresses, countries, time zones, user types, email verification status, last-active dates, last-login dates and dates joined.

The company said it has not yet identified who was responsible for the breach and has found no evidence so far that the stolen data has been published, shared or sold. Mathspace confirmed a total of 1,079,819 people were affected across Australia and New Zealand.

Source

How it could affect your business

Unpatched vulnerabilities are one of the most common and preventable ways attackers gain access to systems. When security patches are available but not applied, organizations are essentially leaving a known door open for anyone looking to walk through it. An automated and proactive patch management strategy that prioritizes timely updates across all systems and software is one of the most effective steps businesses can take to stay ahead of attackers.

United States

Baylor Genetics

Industry: HealthcareExploit: Hacking

A June cyberattack at the Texas-based clinical genomics company Baylor Genetics resulted in the exposure of electronic protected health information (ePHI) belonging to nearly 2.8 million people.

Baylor Genetics, a clinical diagnostic genomics company that provides genetic testing services to hospitals, identified suspicious activity within its computer network on or around June 15, 2026. A subsequent investigation determined that an unauthorized third party accessed a portion of its IT network between June 11 and June 17, 2026. The breach has since been added to the HHS Office for Civil Rights website, confirming that the ePHI of 2,810,878 individuals was exposed or stolen in the incident.

The exposed information includes names, dates of birth, medical testing information, lab test results and health insurance information. A limited subset of patients also had their Social Security numbers compromised.

Source

How it could affect your business

Data breaches at health care providers carry far greater consequences than most other sectors. Medical records, lab results and Social Security numbers combined give attackers everything they need for long-term identity fraud that can be extremely difficult to undo. Affected individuals should monitor their credit reports and insurance statements closely for any unusual activity, place a fraud alert or credit freeze if they suspect misuse and be on high alert for phishing attempts that reference their medical or personal details.

United States

Quinn Emanuel

Industry: LegalExploit: Phishing

Two prominent U.S. law firms, Quinn Emanuel and McDermott, both confirmed data breaches on September 3.

Quinn Emanuel said it identified unauthorized access to stored files through a single temporarily compromised user account within one software application, with a limited number of client documents affected and relevant parties already notified. McDermott separately confirmed an isolated social engineering incident involving a single user and a limited number of documents. It is not clear whether the two breaches were related or who was responsible for either incident.

The two incidents are the latest in a growing pattern of attacks targeting U.S. law firms. Major firms, including Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale, have all reported data breaches in recent months.

Source

How it could affect your business

Law firms hold some of the most sensitive confidential business and personal data of any sector, making them an increasingly attractive target for cybercriminals looking for high-value information. As these incidents show, attackers do not always need to break through sophisticated defenses; a single compromised user account or a successful social engineering attempt can be enough to get in. Regular user awareness training that helps employees recognize and respond to social engineering tactics, such as impersonation, pretexting and manipulation, is one of the most effective lines of defense against this type of attack.

Like what you're reading?

Subscribe now to get security news and information in your inbox every week

Upcoming Webinars

Join other IT professionals to connect, learn and level up. Get insights into the latest cybersecurity trends and technologies.

The New Playbook for MSP Growth: Websites, SEO, AI, and Automation That Actually Convert

The New Playbook for MSP Growth: Websites, SEO, AI, and Automation That Actually Convert

View event
Kaseya DACH Monthly – September Edition

Kaseya DACH Monthly – September Edition

View event
Security Tech Jam: Deploying and Scaling Kaseya SIEM

Security Tech Jam: Deploying and Scaling Kaseya SIEM

View event