SecureFact – September 7, 2026
Major cybersecurity incidents impacted cloud services, identity verification, healthcare, aviation, and health technology organizations, exposing sensitive customer, patient, travel, and identity information while highlighting risks from authentication flaws, third-party vulnerabilities, and data extortion.
Dropbox Accounts Breached Through Lenovo Email Verification Flaw
Approximately 5,000 Dropbox accounts were compromised through a flaw in Lenovo’s email verification process. Attackers exploited the vulnerability to register fraudulent Lenovo IDs using victims’ email addresses, then used these fake IDs to gain unauthorized access to associated Dropbox accounts without requiring passwords. The breach occurred between August 4 and 21, 2026. Affected users’ Dropbox sessions authenticated through Lenovo IDs were immediately expired by Dropbox. The company implemented a new login requirement mandating users enter their Dropbox account password when attempting to use Lenovo ID authentication. Dropbox and Lenovo worked collaboratively to mitigate the risk upon identifying the issue. Some users reported viewing and downloading of their content by the attacker. The investigation determined that Lenovo customers were not affected by the issue, and the vulnerability was related to a legacy integration between Lenovo ID and Dropbox.
(Source: Read full report)
IDScan Sued Over Alleged Data Breach Affecting 153 Million Drivers
Multiple lawsuits have been filed against identity verification company IDScan following a reported breach exposing over 153 million U.S. and Canadian driver’s license scans. The dark-web identity-theft service “Nexus” advertised access to more than 153 million driver’s license scans, 10 million ID cards, 3 million travel documents, and 579,000 medical cards. IDScan’s systems are used across the U.S. in car rental firms, retailers, gun shops, financial institutions, cannabis dispensaries, and hospitality establishments. The FBI’s New Orleans office launched an investigation into the incident. Law firms including Markovits, Stock & DeMarco and Hall Attorneys have launched investigations into potential class-action litigation. IDScan has not published any statements about the allegations and did not respond to requests for comments. The company began notifying some business customers around September 1st. Given the incident’s potential scale, additional lawsuits and potential class actions could be filed, with related cases potentially consolidated into multidistrict litigation.
(Source: Read full report)
French Hospital Fined €500,000 After Breach Exposes Data of 727,000
France’s data protection authority (CNIL) fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data. The security breach in summer 2025 exposed sensitive data belonging to 524,867 patients and 202,246 trusted third parties. An attacker accessed the hospital’s electronic patient record system and extracted sensitive data of more than 727,000 people. CNIL’s investigation identified multiple security failures including external users accessing the system without VPN or multi-factor authentication, inadequate access controls, and lack of real-time monitoring. The hospital lacked real-time or near-real-time monitoring and alerting, allowing the attacker to explore the system and extract large volumes of data over several days without detection. A teen hacker using the alias “Marak” claimed responsibility and attempted to sell the stolen data for €2,000 to €5,000, though it was later reported the data was neither sold nor published. The hospital informed affected patients but did not directly notify the 202,246 trusted third parties whose data was also stolen.
(Source: Read full report)
FulcrumSec Claims Manchester Airports Hack, Theft of 86 GB of Data
The Manchester Airports Group (MAG) data breach was claimed by extortion group FulcrumSec, which stole approximately 86 GB of compressed data (640 GB when extracted). Samples reviewed contained information consistent with MAG’s disclosure while indicating considerably more detailed customer, booking, and travel information than initially revealed. The breach exposed customer data related to Manchester, London Stansted, and East Midlands airports from car park, lounge, and Fast Track bookings and in-airport Wi-Fi registrations. FulcrumSec obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript. The stolen material included a 21.5 GB Manchester customer export containing consolidated profiles combining customer identifiers with historical booking activity and marketing classifications. Nearly 200,000 records related to upcoming travel during the remainder of 2026 were allegedly stolen, containing dates, times, and booking information linked to personally identifiable information. MAG contacted affected customers and advised them to remain vigilant for suspicious emails, text messages, and telephone calls. The incident affected approximately 8.7 million customers, making it the largest known customer data breach affecting a British airport operator.
(Source: Read full report)
Novocure Data Breach Affects More Than 1,400 Cancer Patients
Healthtech company Novocure disclosed that data of an undisclosed number of employees and more than 1,400 U.S. cancer patients was exposed in a mid-August cyberattack. The attackers accessed over 1,400 U.S. patient records with ID numbers, though these records did not contain patient names or other identifying data. For fewer than 50 other patients in the western U.S., threat actors accessed identifying information and general contact information for healthcare providers. The data breach also exposed contact information for an undisclosed number of Novocure employees, including job titles and phone numbers. The ShinyHunters extortion gang claimed responsibility for the attack and leaked a 33GB archive of files allegedly stolen from the company’s systems. Novocure stated that no access to any of its medical treatment devices was obtained and its ability to operate was not compromised. The company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients. Novocure takes its obligation to safeguard privacy and security of patients’ data very seriously.
(Source: Read full report)