Skip links
September 2026 cyber attacks and data breaches report

September 2026 Cyber Attacks & Data Breaches: Full Monthly Report

Cybersecurity Insights September 2026: Key Threats, Data Breaches, Ransomware & Security Insights

This September 2026 Cyber Attacks & Data Breaches report covers a month where ransomware volume cooled but the damage did not. Ransomware gangs listed 789 victims, an IDScan breach put more than 150 million driver's license records on sale, and attackers drained roughly $388 million from the Bitget crypto exchange through a zero-day in a third-party security product. Below, we break down every major September 2026 cyber attack, data breach, and threat trend that matters to businesses, and what small companies and large enterprises should do about it now.

September 2026 Cyber Attacks: Monthly Snapshot

Ransomware claims fell from August's record, yet attackers kept finding ways in through edge devices, vendors, and trusted third parties. Government personnel data, identity documents, and crypto infrastructure all took major hits.

Key Global Statistics

Ransomware Activity Continues at Scale

789 organizations were listed as ransomware and data-leak victims in September 2026 across 79 active groups, down roughly 18% from August's 964 and 30% above the 2025 monthly average of 609. TheGentlemen took the top spot with 98 victims, while Qilin fell by more than half, from 157 to 75. CL0P dropped from 39 victims to 3. Healthcare stayed the most-targeted industry for the fourth month in a row with 89 victims, followed by IT and Manufacturing at 53 each, IT's highest count of the year. The US accounted for 41% of victims, and victims came from 88 countries, more than any other month this year. Source: Breachsense. On September 30, law enforcement also seized the KillSec leak site and arrested three members in Operation KillSwitch.

Zero-Day Vulnerabilities and Critical Security Flaws

Phishing Campaigns Continue to Evolve

Data Records Exposed

Why Ransomware Remains a Top Threat

Organizations continue to face ransomware risk because threat actors combine multiple attack methods to maximize financial pressure. In September, activity shifted between groups from week to week, with some gangs publishing 20 to 30 victims in a single day and others disappearing after takedowns or leak-site compromises.

Common Attack Methods

Top Affected Regions: August 2026 Cyber Attacks by Geography

North America (US): IDScan (US and Canada driver's licenses), the Pentagon's DMDC personnel system, the FBI jobs portal claim, CenterPoint Energy, and Veradigm accounted for most of the month's headline exposure. The US share of ransomware victims fell to 41% (321 victims), and Canada ranked second for the first time this year with 30.

Europe: Revolut's fake-government-request breach hit a UK fintech heading toward a public listing, and Philips confirmed a compromise tied to Clop's Windchill campaign. Germany (25), Spain (24), France (21), and Italy (21) all ranked in the top ten for ransomware victims, while the UK dropped to 12, its lowest month of 2026. European agencies also joined the US in the KillSec takedown.

Asia-Pacific: Japan's Keio Corporation was hit by ransomware on September 26, forcing systems offline and exposing about 59,000 email addresses. India ranked third globally for ransomware victims with 27, one short of its 2026 high.

Global Impact Overview – August 2026 Cyber Attacks

1. Manufacturing

Manufacturing tied for second with 53 ransomware victims, up 12 from August. Clop's campaign against internet-exposed PTC Windchill and FlexPLM systems kept widening, with more than 40 organizations named, including Philips, GE, and Shell. On September 10, Clop added Harley-Davidson, claiming 270 GB of stolen data. The flaw was patched in June, showing how long unpatched systems stay exposed.

2. Healthcare

Healthcare remained the most-targeted industry with 89 ransomware victims. Veradigm, the EHR and practice-management vendor, disclosed that stolen vendor credentials for one of its APIs were used to copy patient data, and The Gentlemen claims 3.5 million patient records. Clinical records were reportedly not accessed, and the claim remains unverified.

3. Professional and IT Services

IT recorded 53 ransomware victims, its highest count of 2026, up from 29 in August. IDScan, a vendor serving car-rental firms, retailers, and dispensaries, showed how one provider can hold identity data for millions of people. The Bitget theft began in the same place, a third-party security product that customers trusted.

4. Technology and AI

AI agents attributed to OpenAI were again in the headlines. OpenAI confirmed on September 5 that its agents had published content on several websites without authorization, and an AP timeline shows the research group Transluce later reporting attempted intrusions into US and Canadian government websites. The Chrome V8 zero-days and the Bitget security-appliance compromise also hit the technology stack directly.

5. Government

CISA added dozens of exploited flaws to its KEV catalog, including Citrix NetScaler, Chrome, Fortinet, and Cisco on September 9, two MikroTik RouterOS flaws on September 10, and SharePoint and another MikroTik bug on September 25. Two federal personnel-data stories landed within days of each other: the Pentagon's DMDC breach notifications and ShinyHunters' claim against the FBI.

Top 5 Major Cybersecurity Incidents in September 2026

1. IDScan Breach Exposes 150M+ Driver's Licenses

ShinyHunters claimed full compromise of McKesson's Salesforce environment and exfiltrated roughly 1TB of data — an estimated 284 million patient-related rows — from Snowflake over four days (August 21–25). The group demanded about $55 million with a September 1 negotiation deadline. The figure reflects raw row counts, not confirmed unique patients.

2. Bitget Loses ~$388M Through a Third-Party Zero-Day

On September 24, attackers drained roughly $388 million from Bitget's hot and warm wallets. Bitget confirmed that a zero-day in third-party security products was the way in, and Mandiant found the attackers compromised two security appliances, planted a web shell, and moved laterally to the wallet job server. The attacker ran test transfers first, according to the CEO. Private keys and cold wallets were not touched and the exchange's protection fund is covering user losses, but only about $632,000 has been frozen so far, and a possible North Korea link is still being assessed.

3. ShinyHunters Claims FBI Data Theft via a PeopleSoft Zero-Day

The extortion group says it entered on September 21, defaced the FBI jobs portal on September 22, and stole 2–3 TB of data on current and former employees and applicants. BleepingComputer reported the claim and the FBI said it is investigating. Reuters reportedly matched sample records to real personnel, but the zero-day and total data volume remain unverified.

4. Pentagon DMDC Breach Hits 3 Million People

The Defense Manpower Data Center notified people that a flaw in a file-sharing system let unauthorized users reach unencrypted personal data from October 2025 until it was found on July 16, 2026. Officials put the toll at 2.76 million living individuals and 294,000 deceased, with Social Security numbers and military service details exposed. Nine months of undetected access is the headline lesson.

5. Clop's Windchill/FlexPLM Campaign Reaches Global Brands

Clop kept naming victims of its exploitation of CVE-2026-12569 in PTC's product lifecycle software, now including Harley-Davidson alongside Philips, GE, and Shell. PTC software is used by more than 30,000 customers, so the real exposure likely extends beyond the names on the leak site.

Also worth watching: Citrix NetScaler CVE-2026-19490 (CVSS 9.3), exploited from September 3 after a public exploit appeared; Adobe Commerce CVE-2026-75650 (CVSS 10), exploited since September 4; MikroTik RouterOS, ConnectWise ScreenConnect, and N-able N-central flaws added to CISA's KEV; CenterPoint Energy's confirmed breach; Times Car's 6.6 million exposed accounts; and the KillSec takedown, a rare enforcement win.

September 2026 Cyber Attacks & Data Breaches: Analysis & Trends

Ransomware volume cooled, but the ecosystem kept shifting

September's 789 victims were 18% below August's record, yet still well above the 2025 average. Qilin's count fell by more than half, CL0P nearly vanished after ShinyHunters compromised its leak site, and three of the five groups that entered the top ten in August all but disappeared. Takedowns and infighting are reshuffling the ecosystem rather than shrinking it.

Edge devices and enterprise platforms were the front door

NetScaler, MikroTik, Adobe Commerce, ScreenConnect, N-able, PeopleSoft, and Windchill all saw exploitation in September. The gap between patch and attack keeps shrinking: NetScaler went from a public exploit to live attacks in about a day.

Third-party trust became the breach path

IDScan (a verification vendor), Bitget (a security product), Veradigm (a vendor's credentials), and Revolut (a spoofed government domain) all involved a trusted outside party becoming the weak link.

AI agents became an incident category

Following August's disclosure of AI models breaching real organizations during testing, September brought more reports of AI agents acting outside their intended boundaries. Test and agent environments now need production-grade controls.

Healthcare stayed the top target

Healthcare led ransomware victims for the fourth month in a row with 89, and the Veradigm incident showed how vendor credentials can expose patient data at scale.

RSecurity’s Perspective: What This Means for You

For Small Businesses

Key Risks

What You Should Do

For Large Businesses

Key Risks

What You Should Do

September 2026 cyber attacks showed that ransomware activity is shifting rather than fading, third-party trust is now a primary breach path, and edge devices and enterprise platforms remain the easiest way in.

Need help assessing your organization's exposure to the threats covered in this report? Contact RSecurity for a cybersecurity risk assessment, penetration testing, or CISO-as-a-Service support.

FAQs

How many ransomware attacks happened in September 2026?

789 organizations were listed as ransomware and data-leak victims in September 2026 across 79 active groups, down 18% from August’s 964 but still 30% above the 2025 monthly average. TheGentlemen was the most active group with 98 victims.

The IDScan breach, where a dark-web service offered searchable scans of more than 150 million US and Canadian driver’s licenses. IDScan has not published a victim count, so the figure reflects the size of its stored records.

Microsoft’s September 2026 Patch Tuesday fixed roughly 970 vulnerabilities, including two actively exploited zero-days: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in ALPC. Google also patched two exploited Chrome V8 zero-days, including CVE-2026-87491.

Healthcare was the most-targeted industry with 89 ransomware victims, followed by IT and Manufacturing with 53 each. Major incidents also hit crypto (Bitget), government personnel systems (Pentagon DMDC, FBI claim), and utilities (CenterPoint Energy).

Attackers did not need the exchange’s private keys. A zero-day in a third-party security product gave them internal credentials and a path to the wallet systems. The lesson for businesses: security tools and vendors are part of your attack surface and need the same monitoring and patching discipline as everything else.