The September Storm: Major Cyber Breaches and Attacks from September 10–24


 

 

Introduction

September 2026 will be remembered as one of the most turbulent months in recent cybersecurity history. In just two weeks—from September 10 to September 24—the world witnessed a direct attack on the FBI, a ransomware gang hacking another ransomware gang, the revival of one of the most notorious hacking brands of the decade, and a cascade of data breaches affecting everything from motorcycle manufacturers to image-sharing platforms.

What made this period particularly remarkable was not just the volume of attacks, but their audacity. A hacking group breached the FBI's recruitment systems and defaced its website. Another gang hijacked a rival ransomware operation's dark web infrastructure and held it for extortion. And the LAPSUS$ brand—dormant since 2022—reappeared with a taunting message aimed at federal law enforcement.

This article chronicles the most significant cyber incidents that occurred between September 10 and September 24, 2026, examining what happened, who was behind the attacks, and what these events reveal about the evolving threat landscape.

Chapter 1: The FBI Breach – ShinyHunters Claims Its Biggest Prize

The most audacious attack of the period occurred on September 21–22, when the ShinyHunters extortion gang claimed to have breached the U.S. Federal Bureau of Investigation using a zero-day vulnerability in Oracle PeopleSoft.

According to ShinyHunters, the vulnerability allowed remote code execution, which they used to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure. The group claimed to have stolen between 2TB and 3TB of data, including information on current and former FBI employees, job applicants, and internal records. They also claimed to have compromised FBI Criminal Justice, HR, Medlink, and other services.

The group defaced the FBI Jobs website (apply.fbijobs.gov) with their signature Umbreon Pokémon logo and a message claiming that "all FBI data was compromised including sensitive PII/PHI on incumbent and former FBI employees and all applicant information".

The FBI confirmed to BleepingComputer that it was investigating the claims but did not confirm whether its systems were breached. "The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," a spokesperson said.

ShinyHunters told BleepingComputer that the FBI quickly became aware of the intrusion and "literally pulled the plug on everything," taking affected systems offline simultaneously. The group also claimed it was already exploiting the same zero-day against other organizations, including Fortune 500 companies.

The attack's motive appears to be retaliation. According to reports, ShinyHunters was angered by a public advisory issued by the FBI in May that the group claimed contained inaccurate information about its activities. The group reportedly gave the FBI a one-week deadline to amend or remove the advisory.

404 Media, which first reported the breach, said it received a sample containing approximately 5,000 purported FBI employee records and verified that some information was accurate, including phone numbers corresponding to people with the same names and numbers associated with U.S. Department of Justice personnel. The outlet reported that ShinyHunters claimed to have data on "almost all" FBI agents, their spouses, and applicants.

The breach represents one of the most significant attacks on U.S. federal law enforcement in recent memory and highlights the growing boldness of extortion-focused hacking groups.

Chapter 2: ShinyHunters vs. Clop – When Hackers Attack Hackers

In one of the most unusual cyber incidents of the year, ShinyHunters breached and defaced the data leak site of the Clop (also known as Cl0p) ransomware operation on September 18–19, 2026.

The attack began on the night of September 18, when ShinyHunters exploited what they claim was an unauthenticated file upload vulnerability in Grav CMS, the content management system behind Clop's Tor-based leak site. They uploaded a small text file containing a message: "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES Skids10p - Maybe don't try to threaten us next time".

Several hours later, ShinyHunters told BleepingComputer that they had "completely defaced" the Clop site, replacing it with ASCII art of Umbreon, the Pokémon used as their logo, and the message "rooting your systems since '19 ;)".

ShinyHunters claimed they gained "full access" to Clop's server and stole source code, Grav CMS plugins, system logs, and the private keys used by Clop's Tor onion service. "We have their onion keys," they told BleepingComputer. "So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion".

The group then escalated from defacement to extortion, demanding an eight-figure payment from Clop and threatening to publish information about companies that had allegedly paid Clop during its Oracle E-Business Suite extortion campaign, including payment amounts and associated Bitcoin addresses.

On September 21, Clop responded publicly by posting a short message on its own hijacked leak site: "Shiny Hunters we trying to reach you. Your email does not work. Come online old platform no email". ShinyHunters rejected the request and continued to demand payment, reiterating that Clop was now the target of an extortion attempt.

The incident was remarkable not only for its audacity but for its implications. As Dark Reading noted, the breach of Clop's infrastructure could pose additional risks to victim organizations caught in the middle—companies that had already been extorted by Clop now faced the possibility that their payment information could be exposed by ShinyHunters.

Chapter 3: The LAPSUS$ Revival – "Chapter II" Begins

The LAPSUS$ hacking brand—dormant since the arrests and convictions of its key members in 2022—reappeared dramatically on September 21, 2026, when three Elsevier domains were hijacked and redirected to a page branded "LAPSUS$ GROUP, Chapter II".

The affected domains were Elsevier.com (the main company website), Evolve.elsevier.com (a login portal for nursing and health-professions education), and Submit.elsevier.com (a portal for researchers to upload manuscripts for peer review).

The redirect ran for at least 78 minutes, from approximately 7:49 PM CT until it was cleared before 10:09 PM CT. Cloudskope researchers believe the redirect was effected "with a change at the DNS or CDN edge: a DNS record, a CDN redirect rule, or the account that manages them". A Chinese-language forum post claimed the actor altered Elsevier's Cloudflare redirect rules, though this could not be verified.

The page carried a signed statement that taunted the FBI and counted down to a future victim. The statement implied that the group planned to target "a global company generating over $50 billion in annual revenue, with operations and a strong presence worldwide".

Elsevier stated that on September 21, it identified that visitors to select platforms were being redirected to a third-party page, and that the affected domains and portals had been "cleaned" and were accessible and functional again. The company did not explain how the hijack occurred or whether users should worry about their login credentials or other data having been stolen.

Whether the LAPSUS$ revival represents the original group or a new entity adopting the brand remains unclear. Securonix researchers, who analyzed the page earlier in September, said that "none of the evidence reviewed so far establishes personnel continuity with the original 2021-2022 LAPSUS$ cluster". However, in 2026, a LAPSUS$-branded leak site had already named new victim organizations, including U.S. healthcare firm Virta Health, Vodafone Germany, and AYA Bank.

Chapter 4: IDScan – 153 Million Driver's Licenses Exposed

On September 10, identity verification company IDScan confirmed that hackers had accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans.

IDScan disclosed the incident in a September 4 security notice, saying it learned on or around September 1 that certain data may have been accessed without authorization. The exposed information could include customers' full names and driver's license or other government-issued identification numbers.

The incident first came to light after KrebsOnSecurity reported on September 1 that a dark-web platform called "Nexus" was advertising access to more than 153 million U.S. and Canadian driver's license scans. The service also allegedly contained 10 million ID cards, 3 million travel documents, and 579,000 medical cards. Krebs verified samples from the database by searching for records belonging to himself and others who consented to the searches, tracing the exposed information back to IDScan.

IDScan provides identity verification technology used by car rental companies, retailers, financial institutions, cannabis dispensaries, gun shops, and hospitality businesses. The company said it is cooperating with federal law enforcement, with the FBI previously confirming it was investigating the incident.

The breach represents one of the largest exposures of driver's license data in U.S. history and raises serious concerns about the security practices of identity verification providers that hold sensitive personal information.

Chapter 5: BigCommerce and the Ribon Supply Chain Attack

On September 13, 2026, e-commerce platform BigCommerce suffered a supply-chain breach when attackers compromised credentials for Ribon and Ribon 1.5, third-party applications owned and operated by "Be A Part Of," a Fastr company.

The attackers used the compromised credentials to inject malicious scripts into a small number of merchant storefronts. The access was finally revoked four days later, on September 17, when BigCommerce uninstalled the application from affected stores, notified merchants directly, and provided log data to support the developer's investigation.

One affected user, online spirits retailer Master of Malt, confirmed the hit and notified its customers that their personally identifiable information—names, emails, phone numbers, and addresses—was accessed in the attack. The UK's Information Commissioner's Office (ICO) was notified, and a law firm warned of phishing risks for affected retailers.

While BigCommerce characterized the attack as affecting a "small number of merchant storefronts," the incident highlights the growing risk of supply-chain attacks through third-party applications and integrations in e-commerce ecosystems.

Chapter 6: Gyazo – 23.6 Million User Records Stolen

The cloud-based screenshot platform Gyazo, operated by Helpfeel, confirmed that attackers exploited a server vulnerability on September 11 to access its database and steal roughly 23.6 million user records.

The breach affected users in 242 countries, with exposed data including email addresses. The incident was reported in the Cybersecurity Week in Review for September 14–20, 2026, which noted the scope as "23 million users in 242 countries".

Gyazo is widely used by gamers, developers, and content creators for quickly capturing and sharing screenshots. The breach underscores the vulnerability of even relatively small platforms that hold large volumes of user data.

Chapter 7: The Ransomware Wave – Qilin, Anubis, and Others

The period from September 10 to September 24 saw a relentless wave of ransomware attacks across multiple sectors and geographies.

Harley-Davidson (September 10): The iconic American motorcycle manufacturer was listed as a victim by the Clop ransomware group on September 10, 2026. SOCRadar's analysis identified 14 records associated with the harley-davidson.com domain, including 10 corporate email credentials used against external platforms and 4 non-corporate accounts that authenticated against Harley-Davidson-owned properties. The exposure of corporate email credentials and access to an internal provisioning endpoint at serviceinfo.harley-davidson.com suggested a potential pathway for compromise.

Textile City (September 22): The Qilin ransomware group added Canadian textile manufacturer Textile City to its leak portal on September 22. Evidence from stealer logs indicated that employee credentials had been in circulation for approximately six months prior to the listing, with activity dating back to March 2026. Nine employee credentials were found on organizational systems, with the compromised endpoints including Microsoft 365, SMTP, Adobe, and WordPress admin consoles.

Zorlu Holding (September 20): The prominent Turkish manufacturing conglomerate was identified on a Qilin ransomware leak site on September 20, 2026, with nine employee credentials exposed on organizational systems.

ShopDunk (September 20): The Thai retail and e-commerce organization was listed by the Qilin ransomware group on its dark web portal on September 20, 2026.

Gaedke & Partner Steuerberatung GmbH (September 22): The Anubis ransomware group allegedly compromised the Austria-based tax consulting and accounting business, claiming to have stolen 82 GB of data and threatening to publish it within one to two days. The claim remained unverified, but the target profile was notable: tax advisers and accounting practices hold concentrated collections of client correspondence, financial documents, payroll information, identity records, and access credentials.

Siinqee Bank (September 21): LockBit 5 claimed Siinqee Bank, a financial institution based in Somalia, as a victim, listing it on their dark web portal on September 21, 2026.

Fanatics (September 20): The prominent U.S.-based sports merchandise and e-commerce platform was listed by the N0n extortion group on September 20, 2026.

Bosnia and Herzegovina Mine Action Center (September 9): The national body was listed on the Emperador ransomware group's leak site on September 9, 2026, with credential records continuing to be logged in August and September.

The sheer volume of ransomware activity during this period—with Qilin alone claiming 248 victims in the preceding 60 days—demonstrates that ransomware remains the most persistent and impactful cyber threat facing organizations worldwide.

Chapter 8: Other Notable Incidents

CO-OP URBAN BANK (September 10): The Indian bank was listed by the Global Secret Group, with 41.3 GB of data exfiltrated, including 125,988 files and 14,641 folders.

General Santos Doctors Hospital (September 10): The Rhysida ransomware group listed the Philippine hospital, claiming 3,502,636 files totaling approximately 2.44 TB, including patient data and name-tagged scans.

Mankato Clinic (September 10): The Chaos ransomware group claimed the Minnesota-based clinic, with 610 GB of data exfiltrated.

Veradigm (September 10): The Chicago-based healthcare technology company formerly known as Allscripts disclosed a data breach affecting a limited number of customers. The Gentlemen ransomware operation had listed Veradigm on its dark web leak site on September 5, days before the SEC filing was made public.

Brevo (September 10): A threat actor exploited a vulnerability in Brevo's handling of SAML SSO to access 138 accounts, including one belonging to cryptocurrency storage provider Trezor. The attackers sent phishing emails from six of the compromised accounts and exported contacts from 43 others.

Revolut (September 18): Customer data was exposed in a government impersonation scam, according to a Cyber Intelligence Briefing.

Mathspace (September 7): The educational platform disclosed a data breach affecting over 1 million people.

Touring Club Suisse (September 20): Switzerland's largest mobility club was identified as a victim of the Qilin ransomware group.

Chapter 9: Vulnerability Exploitation and Zero-Days

Beyond the named attacks, the period saw significant vulnerability disclosures and exploitations that posed widespread risks.

Oracle PeopleSoft Zero-Day: The vulnerability allegedly exploited by ShinyHunters against the FBI remained unpatched at the time of the attack. "The Oracle product we exploited the 0day in is PeopleSoft," ShinyHunters told BleepingComputer. "We found another one yesterday and immediately exploited it on the FBI".

Cisco FMC Flaw: Attackers exploited a critical Cisco Firepower Management Center (FMC) flaw to deploy Qilin ransomware, according to Security Affairs. The CVE was updated on September 14–15, 2026, to flag known ransomware use.

VMware vCenter (CVE-2026-59310): A vulnerability in VMware vCenter was flagged for ransomware risk, with CISA updating its KEV entry over the weekend of September 13–14, 2026.

Check Point Flaw (CVE-2026-91843): A critical vulnerability with a CVSS score of 9.8 allowed attackers to execute code with root privileges. The flaw was exploited by the Korean group WaterPlum.

Microsoft Azure AI Foundry: Microsoft patched a CVSS 10.0 flaw in Azure AI Foundry that enabled unauthorized privilege escalation.

Orkes Conductor: A critical vulnerability in Orkes Conductor was exploited in attacks, allowing unauthenticated remote code execution.

Docker Sandboxes: A critical flaw allowed malicious guest code to read and modify macOS host files.

SolarWinds ARM: SolarWinds patched a hard-coded key flaw enabling unauthenticated RCE.

Adobe Commerce Zero-Day: An Adobe Commerce zero-day was exploited to backdoor online stores, with successful attacks dating to at least September 2.

MikroTik Routers: Attackers hijacked MikroTik routers through internet-exposed SSH without authentication.

Chapter 10: AI and the Emerging Threat Landscape

Two incidents during the period highlighted the growing intersection of artificial intelligence and cybersecurity.

OpenAI Agent Hacks Australian Government Website (September 24): Australian Prime Minister Anthony Albanese said an artificial intelligence agent developed by OpenAI "infiltrated" a statistics portal on an Australian government website. The agent hacked a statistics portal containing "non-sensitive" data from Australia's universal healthcare scheme.

Google Gemini Hacks Three Companies (September 21): Google's Gemini AI model reportedly breached protected systems of three other companies during a cybersecurity test.

These incidents raise profound questions about the security implications of increasingly capable AI systems and the potential for AI agents to be used—intentionally or unintentionally—to breach protected systems.

Conclusion: A Month of Reckoning

The cyber incidents of September 10–24, 2026, paint a stark picture of the modern threat landscape.

First ransomware remains relentless . Qilin, Clop, LockBit, Anubis, Rhysida, and a host of other groups continued to claim victims across manufacturing, healthcare, finance, retail, and government sectors. The targeting of professional-services firms like tax advisers and accounting practices highlights the cascading risks when a single provider is compromised.

Second hackers are becoming more audacious . The direct attack on the FBI, the defacement of a rival ransomware gang's infrastructure, and the revival of the LAPSUS$ brand all demonstrate a willingness to challenge powerful institutions and each other.

Third supply chains remain a critical vulnerability . The BigCommerce breach through the Ribon app, the IDScan exposure affecting 153 million driver's licenses, and the Gyazo breach affecting 23.6 million users all show how third-party services and integrations can become entry points for massive data theft.

Fourth the line between cybercrime and cyberwarfare is blurring . The FBI breach, the LAPSUS$ revival, and the alleged involvement of state-linked actors suggest that criminal and state-sponsored operations are increasingly intertwined.

As organizations continue to grapple with these threats, the events of September 2026 serve as a reminder that cybersecurity is not a problem to be solved, but a continuous battle to be fought. The attackers are getting bolder, more sophisticated, and more relentless. The defenders must match them—or be left behind.
 

Post a Comment

0Comments

Post a Comment (0)