The week of 07 to 13 September 2026 was defined by identity compromise, not software exploits. Five incidents drove the week: a Cisco Secure Firewall Management Center authentication bypass under simultaneous nation-state and ransomware exploitation, a confirmed breach at identity-verification vendor IDScan.net exposing more than 150 million driver’s license records, a vendor API credential theft at health IT company Veradigm, a Florida DMV database accessed through a police officer’s personal-device credentials, and a Revolut data leak triggered by a fraudster impersonating a government agency’s own email domain. None of the five involved a novel technique. Every one of them worked because a credential, a session, or a request looked legitimate enough to be trusted. That pattern matters more than any single number this week, since 22 percent of breaches already start with credential abuse and these five incidents show why that share keeps growing rather than shrinking.
1. Cisco Secure Firewall Management Center exploited by nation-state and ransomware actors in parallel
Overview: Cisco Talos confirmed on 9 September 2026, with an update the following day, that it is actively tracking exploitation of two Secure Firewall Management Center (FMC) vulnerabilities, CVE-2026-20079 and CVE-2026-20316, by three distinct intrusion clusters.
Impact: Cisco has not disclosed how many FMC deployments were compromised or the scope of data accessed in any single intrusion. What is known: CVE-2026-20079 carries a CVSS score of 10.0 and allows an unauthenticated attacker to obtain root-level control of the underlying operating system, and CVE-2026-20316 (CVSS 5.3) exposes static credentials on a low-privileged account. CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog on 9 September 2026 with a federal remediation deadline of 12 September 2026.
Details: Talos attributes one cluster, tracked as UAT-11823, to tooling that overlaps with the Sandworm APT group with high confidence, including deployment of malware linked to the Cyclops Blink framework. A second cluster, UAT-11988, is assessed with high confidence to be a ransomware operator using tactics consistent with Qilin ransomware affiliates. Talos was explicit that the attribution is based on tooling and tactic overlap rather than direct confirmation that Sandworm or Qilin themselves are behind the activity, a distinction FMC operators should not read past. Both clusters exploit the same authentication bypass (MITRE ATT&CK T1190, exploitation of a public-facing application) to reach FMC’s web interface without credentials.
Remediation guidance: Apply Cisco’s released hotfixes immediately rather than waiting for the comprehensive hardening release scheduled for the week of 16 September 2026. Hunt for the indicators of compromise Talos published for both the Sandworm-linked and Qilin-linked clusters. Remove FMC’s web management interface from direct internet exposure if any deployment currently allows it.
2. IDScan.net confirms breach exposing more than 150 million driver’s license records
Overview: IDScan.net, an identity-verification vendor used by businesses ranging from entertainment venues to cannabis dispensaries, confirmed on 10 September 2026 that hackers stole driver’s license and other government-issued identity document data from its cloud systems.
Impact: IDScan confirmed more than 150 million driver’s license records were taken. Independent researchers who first identified the data for sale on a dark web marketplace put the more precise figure at 153 million records, a number IDScan has not separately confirmed or disputed. The stolen data includes full names, driver’s license numbers, and identity numbers from other government documents including passports. Reporting identified at least one high-profile individual, U.S. Secretary of Defense Pete Hegseth, among the exposed records.
Details: IDScan received notification of the intrusion around 1 September 2026, nine days before its public confirmation. The company has not disclosed the technical entry point. The FBI and the Pentagon are investigating, reflecting the downstream reach of a single identity-verification vendor into government and defense personnel records it never directly collected.
Remediation guidance: Any organization using IDScan.net or a similar identity-verification vendor should confirm with the vendor whether its specific customer data was among the records taken, rather than assuming scope from press coverage. Treat driver’s license numbers exposed in this breach as compromised for identity-proofing purposes going forward. Review which third-party identity-verification vendors hold copies of government ID images and whether that retention is contractually necessary.
3. Veradigm discloses vendor API credential theft as ransomware gang claims 3.5 million records
Overview: Health IT vendor Veradigm disclosed on 9 September 2026 that an attacker obtained credentials from a third-party vendor’s environment and used them to access a Veradigm API reserved for customer services, exposing Social Security numbers and personal details for what the company describes only as a small number of customers.
Impact: Veradigm has not published a specific number of affected individuals or records. The Gentlemen ransomware gang separately claims to hold 3.5 million patient records, including full names, home addresses, Social Security numbers, and personal guarantor information, and threatened to publish the data if a ransom was not paid by 11 September 2026. Veradigm has not confirmed that figure, and the gap between a confirmed “small number of customers” and a claimed 3.5 million records is stated here, not resolved, because neither side has produced evidence settling it.
Details: The attack path ran through a vendor’s environment rather than Veradigm’s own perimeter: stolen vendor credentials granted access to an API scoped for customer service functions (MITRE ATT&CK T1078, valid accounts). Veradigm states clinical and medical information remained secure, which narrows the exposure to identity and financial fields rather than treatment records.
Remediation guidance: Scope every vendor-facing API to the minimum function it needs and issue short-lived, rotated credentials rather than standing vendor access. Add anomaly detection for API call volume and query patterns tied to vendor-linked accounts specifically, since that traffic often looks legitimate by design. Require vendors to attest to their own credential handling as a contractual condition, not a one-time questionnaire.
4. Florida’s DAVID driver database breached through a police officer’s personal-device credentials
Overview: Florida’s Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed on 11 September 2026, after discovering the intrusion on 4 September 2026, that its DAVID driver database was accessed using compromised credentials belonging to a Plant City Police Department user.
Impact: FLHSMV has declined to confirm the scope of records accessed. ShinyHunters, the group claiming responsibility, asserts it stole more than 200,000 driver records complete with driver’s license photos, a figure FLHSMV has not verified. FLHSMV’s own investigation identified a different access vector than the one ShinyHunters described publicly, which means the group’s account of how it got in should not be taken as settled fact alongside the confirmed one.
Details: The credentials belonged to a Plant City Police Department employee and had been improperly stored on that employee’s personal electronic device, outside any agency-managed system. From there, the credentials provided access to DAVID, a statewide database well beyond the scope any single local police department needs for routine work.
Remediation guidance: Prohibit storage of law-enforcement or inter-agency system credentials on personal devices, and enforce that policy technically rather than by memo, for example through conditional access tied to managed devices. Require hardware-bound multi-factor authentication for any account with access to statewide data-sharing systems like DAVID. Audit which local and municipal accounts hold standing access to state-level databases and scope that access down to specific, logged queries rather than broad standing sessions.
5. Revolut confirms customer data exposed to a fraudster impersonating a government agency
Overview: Fintech Revolut confirmed on 12 September 2026 that it disclosed sensitive customer data to an unauthorized party that used a legitimate government agency’s own email domain to submit fraudulent requests for information.
Impact: Revolut says a “limited” number of customers were affected but has declined to give an exact number or confirm whether the incident was contained to specific markets. The exposed data includes identity and contact details such as date of birth, postal address, email, and phone number, along with copies of identity documents including passports and driver’s licenses, and possibly verification selfies, account statements, and transaction histories.
Details: The attacker did not breach Revolut’s systems technically. Instead, they used a compromised or spoofed government agency email domain to submit what appeared to be a legitimate legal or regulatory data request, and Revolut’s own response process handed over customer records to that request. Revolut has not disclosed which government agency’s domain was involved.
Remediation guidance: Require out-of-band verification, such as a callback to an independently sourced phone number, for any law-enforcement or government data request before releasing customer records. Add a mandatory secondary approval step for any request involving identity documents or financial history. Maintain and check incoming requests against a verified registry of known government agency contacts rather than trusting domain appearance alone.
Related reading
- Weekly Cybersecurity Intelligence Report: Cyber Threats and Breaches, 31 Aug to 6 Sep 2026: last week’s edition covered the same IDScan.net data first surfacing on a dark web marketplace, before the company’s own confirmation this week closed the gap between claim and disclosure.
- Coupang data breach: an earlier example of credential abuse producing a delayed-detection breach at large record-count scale, the same pattern behind this week’s Florida DMV and IDScan.net incidents.
How FireCompass helps
Four of this week’s five incidents trace back to a credential or a trusted-looking request rather than a new exploit, which is exactly the class of exposure that a point-in-time scan misses and a continuously running program catches: a credential that was valid on Monday and should have been revoked by Wednesday, or an internet-facing management interface that should never have been reachable in the first place. FireCompass validates exposures with proof-of-concept evidence rather than flagging theoretical findings, which is why its false positive rate stays under 2 percent against 40 to 70 percent for traditional scanners. The gap that keeps producing weeks like this one is structural: CVEs are exploited in about 3 days on average, while most organizations still test their external footprint on an annual cadence measured in months.
See where you stand before attackers do
Run FireCompass’s continuous, evidence-based exposure validation against your own credentials, APIs, and internet-facing management interfaces before they end up in next week’s report.
