Skip to main content
Emerging ThreatsData Breaches

Breaches Expose Sensitive Data at Dropbox, Healthcare Firms

Hospital corridor with people in distance, medical records desk with laptop and papers in foreground.

“More than 150 million driver’s licenses were compromised, as reported by independent journalist.”

Dropbox: around 5,000 accounts hit via a third party

Around 5,000 Dropbox accounts were compromised after an unauthorized user gained access to certain accounts via a third party infrastructure. The detail that the access came through a third party — rather than direct exploitation of Dropbox credentials or services — places the emphasis on external integrations and service relationships as the vector for this incident.

IDScan: more than 150 million driver’s licenses exposed

Independent reporting flagged a large-scale exposure: more than 150 million driver’s licenses were compromised. The source provides no additional technical detail, but the magnitude alone—well into nine digits—marks this as the largest single-item exposure in the set of incidents summarized for September 2026.

Veradigm: patient Social Security Numbers affected, clinical data reportedly safe

Healthcare technology organization Veradigm was exposed due to a third-party breach. According to the report, clinical and medical information were unaffected, while patient Social Security Numbers were compromised. The contrast between unaffected clinical records and exposed Social Security Numbers focuses attention on how different categories of patient data were segmented or protected — and how certain identifiers may have been aggregated in locations the third party controlled.

AdaptHealth: more than 4 million individuals' personal data compromised

AdaptHealth sustained a breach in which more than 4 million individuals had their personal data compromised. The report does not specify categories of the personal data or the mechanism of intrusion, but the head-count places this event among large-scale consumer-data incidents for the month.

FBI employee data reportedly taken by ShinyHunters

The FBI was reportedly hacked by ShinyHunters, who claimed the compromise included the names, addresses, phone numbers, and even spousal information of employees and applicants. The report frames the incident as a collection of personally identifying details tied to personnel and prospective personnel, rather than operational case files or classified material according to the provided description.

What this means for technologists, policymakers, and end users

Technologists and security teams: Two of these summaries — the Dropbox and Veradigm items — explicitly mention third-party involvement. Teams responsible for vendor risk and third-party integrations will, on the facts given, need to re-evaluate where high-value identifiers (Social Security Numbers, driver’s licenses) are shared or stored by outside providers and how access to those repositories is governed.

Policymakers and regulators: The IDScan report’s figure—more than 150 million driver’s licenses—presents a scale of exposure that is likely to draw attention from oversight bodies concerned with identity documentation and data processors that handle large pools of government-issued identifiers. The summary of FBI personnel data may also prompt questions about personnel-data protections and applicant-data handling.

End users and the general public: The incidents described include exposures of Social Security Numbers, driver’s licenses, and contact and spousal information. For people named in the affected sets, the immediate takeaway from the source material is heightened risk of identity misuse tied to those exposed identifiers and contact details.

Taken together, the five items summarized for September 2026 map a narrow but clear pattern: exposures ranged from approximately 5,000 cloud accounts to more than 150 million driver’s licenses; third-party infrastructure is cited explicitly in multiple cases; and the types of data disclosed include government-issued identifiers, Social Security Numbers, and personal contact and familial information. The public record presented here leaves open which vendors or remedial actions will follow and which notifications have been completed — facts the named incidents themselves do not supply.

Read the original report: https://www.securitymagazine.com/articles/102552-5-data-security-stories-to-know-about-september-2026