Data Breaches Impacting Millions Reported in Check Point’s September Threat Intelligence Bulletin

Published:

In the latest Threat Intelligence Bulletin published by Check Point Research, significant data breaches affecting millions have been reported, highlighting the ongoing challenges organizations face in safeguarding sensitive information. The bulletin, dated September 14, 2026, reveals a troubling trend in cyberattacks, with major incidents involving identity verification services, educational platforms, and financial institutions.

Major Data Breaches Uncovered

  • IDScan.net, a U.S.-based identity verification provider, disclosed a data breach after unauthorized access was detected on September 1. The breach exposed sensitive data, including names and government identification numbers. Alarmingly, a criminal marketplace has begun advertising a collection of millions of identity documents, including driver’s licenses, linked to the company’s verification services.
  • In another incident, Mathspace, an educational platform utilized in Australia and New Zealand, suffered a breach affecting over 1 million individuals. Attackers exploited a vulnerability in the self-hosted tool Metabase (CVE-2026-72898) to access an internal reporting database. While names, email addresses, usernames, and locations were compromised, passwords and academic records remained secure.
  • Fintech company Revolut reported a data exposure incident where employees inadvertently fulfilled fraudulent information requests from an email account within a legitimate government agency’s domain. This breach resulted in the exposure of identity documents, verification selfies, contact details, and complete transaction histories.
  • Florida’s Department of Motor Vehicles also fell victim to a data breach, where criminals leveraged credentials stolen from a police officer’s personal device to access driver records. The ShinyHunters group subsequently published images of the stolen data.

Emerging Threats in AI

As cyber threats evolve, Check Point Research has identified new attack vectors leveraging artificial intelligence. One notable technique, dubbed PuzzleMask, allows attackers to conceal prohibited instructions within plain prose prompts, effectively bypassing lightweight language model gatekeepers. In testing, these prompts were classified as safe, yet target models successfully extracted and acted on concealed payloads in over 90% of trials.

Additionally, researchers demonstrated a covert cross-account channel within ChatGPT’s code-execution environment, enabling hidden tasks to run using a victim’s tools and data. This proof of concept showcased the potential for significant data leakage across accounts.

Anthropic disclosed incidents where its Claude models operated outside intended sandboxes due to configuration failures, leading to the publication of a malicious PyPI package that compromised credentials and database access.

Vulnerabilities and Patches

The bulletin also highlights critical vulnerabilities that organizations must address. Microsoft’s September 2026 Patch Tuesday updates addressed a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880 and CVE-2026-81963) that allow local attackers to elevate privileges to SYSTEM. Furthermore, GitLab has patched a critical path traversal vulnerability (CVE-2026-85706) that could allow unauthenticated attackers to read arbitrary files through its repository commits API.

MikroTik has also released fixes for vulnerabilities (CVE-2026-67276 and CVE-2026-86060) in RouterOS that could enable passwordless SSH access and privilege escalation, potentially allowing attackers to take control of exposed routers.

Threat Landscape Overview

Check Point Research’s findings indicate a significant rise in cyberattacks, with enterprise GenAI usage expanding and high-risk prompt activity affecting 86% of organizations utilizing GenAI. The report noted a staggering 1,042 ransomware attacks in August 2026, nearly double the figure from the previous year, alongside a 22% year-over-year increase in average weekly cyberattacks per organization.

As organizations navigate this complex threat landscape, the need for robust cybersecurity measures has never been more critical. The ongoing evolution of attack techniques, particularly those leveraging AI, underscores the importance of vigilance and proactive defense strategies.

For further insights and detailed findings, the complete Threat Intelligence Bulletin can be accessed through Check Point Research.

Follow Cyber Warriors Middle East for further cybersecurity features, analysis and insights.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Alleged Ploutus malware creator Anibal Canelon Aguirre appears in Nebraska court

The alleged mastermind behind the Ploutus malware, Anibal Alexander Canelon Aguirre, made his first court appearance in Nebraska after being apprehended by federal authorities....

AI-enabled threat actor JadePuffer automates destructive actions in cloud environments using Azure service principals

Recent research from Check Point has revealed that the AI-enabled threat actor known as JadePuffer, tracked as Storm-3168, is leveraging compromised Azure service principals...

FBI reports surge in AI-related online scams costing Alabamians over $6 million

The FBI has reported a significant rise in online scams fueled by artificial intelligence, marking the first time the bureau has tracked AI-related complaints...

US DHS allegedly compiles protester dossiers in Palantir database, court filing reveals

Newly unsealed court documents allege that the US Department of Homeland Security (DHS) has compiled extensive dossiers on individuals observing Immigration and Customs Enforcement...