Breach Roundups

September 2026 Breach Roundup: 13.6 Million Records, and the Passwords Are Back

October 5, 2026
September 2026 breach roundup shown as a film strip of five frames: Manchester Airports 8.4M, Chess.com 4.7M, Baxter International 489K, Fanlore 145K and LegionProxy 10K records, the last two marked as containing passwords; 13.6 million records added

Five breaches were added to the XposedOrNot index in September. Between them: 13.6 million records.

That’s the fewest additions of any month this year. August had nine, July thirteen.

And yet I wouldn’t call September quiet, because two things changed that the headline count hides. Passwords came back. And one entry wasn’t a hack at all.

Quick context if you’re new to these. I run XposedOrNot, a free, open-source service: type in an email address and it tells you which public breaches it turns up in. Behind it is a catalog of 787 breaches, 11,633,142,187 records as of the last count.

I pulled every number below from it on the morning of 5 October 2026.

The short version

  • Five breaches, 13,680,402 records. Manchester Airports Group is 61% of the month on its own.
  • Two of the five contain password hashes (Fanlore and LegionProxy). August had none in nine.
  • Chess.com wasn’t broken into. Its 7.3 million rows were scraped from public profiles, and 4.6 million unique emails came along for the ride.

What landed in the index

Every entry is verified and searchable. Counts are records, not people. (You can turn up twice in the same breach, and I often do.)

Breach Happened Records Reached the index after Passwords in the data?
Manchester Airports Group Aug 2026 8,379,476 5 weeks No
Chess.com Aug 2026 4,656,591 8 weeks No
Baxter International Aug 2026 488,992 5 weeks No
Fanlore Aug 2026 145,195 8 weeks Yes, hashed
LegionProxy Apr 2026 10,148 26 weeks Yes, hashed

Four of the five happened in August. So this is really the second half of August’s story, with one straggler from April tacked on at the end. The median gap from breach to searchable was 55 days.

Horizontal timeline of the five September 2026 additions, each bar running from the month the breach happened to the day it entered the XposedOrNot index: Manchester Airports Group 33 days, Chess.com 57, Baxter International 34, Fanlore 55, LegionProxy 180; the two bars with hashed passwords in red

A few rows deserve more than a row.

Manchester Airports Group is the one to check if you’ve flown from the north of England. MAG runs Manchester, Stansted and East Midlands. The group disclosed the theft on 27 August, and the data (8.4 million email addresses with phone numbers, vehicle registrations, parking history, Fast Track and lounge bookings) was published by a group calling itself FulcrumSec. It was searchable here on 3 September, seven days after the disclosure.

Think about what a parking record gives a scammer. Your car’s registration, the dates you were away, your phone number. “We’re calling about a problem with your airport parking booking” is a sentence that lands very differently when the caller already has all three.

Chess.com is a scrape, not a break-in. Nobody got inside Chess.com’s servers, as far as the reporting goes. Someone pulled 7.3 million user records from the platform’s public-facing features over about a week in late July and early August, then gave the file away on two forums. The platform itself described it as mass scraping.

So why index it? Because 4.6 million of those rows carry an email address, and an email next to a username, a real name, and a country is exactly the kit a phishing crew wants.

Stolen or collected makes no difference to the person who gets the email. (We’ve kept the catalog entry honest about the method, though. The description says scraped.)

Baxter International is another CRM export. 7.1 million Salesforce records, 489 thousand unique email addresses with names and physical addresses, leaked after the company declined to pay. Same playbook as Questel and Sharecare in August, same group named in the reporting. If your work address is in it, this is a tell-your-IT-team breach, not a change-your-password one.

Fanlore is small, and it’s the one I’d act on first. Fanlore is the fan-culture wiki run by the Organization for Transformative Works (the AO3 people, though AO3 wasn’t touched). The OTW found the intrusion on 6 August and published a full write-up, which is more than most companies ten times their size manage. The haul was 145,195 email addresses with usernames and password hashes. Old accounts had theirs kept as MD5, newer ones as PBKDF2.

MD5 is the bit that worries me. If you made a Fanlore account years ago and used that password anywhere else, treat it as burned.

LegionProxy is the straggler. A residential proxy service, 10,148 customers, bcrypt password hashes, a breach from April. It only reached us on 28 September, 180 days after the fact. It also happens to be the 79th breach of 2026 in our catalog, the one that broke the yearly record I wrote about last week.

Why “quietest month” is the wrong headline

Here’s the number I’d put on the wall: 13, then 9, then 5. Monthly additions to the index for July, August and September.

Column chart of breaches added to the XposedOrNot index each month of 2026: January 6, February 21, March 16, April 22, May 13, June 23, July 13, August 9, September 5, with September highlighted

Three straight months of decline. Tempting to read that as the world calming down. It isn’t.

Two things are going on. First, the groups that drove the summer (one name appears in five of August’s nine) publish in bursts, and September’s burst mostly landed in the news rather than as verified data. More on that in the radar section below.

Second, and I’ll be honest about this one, our own backlog. Several breaches that surfaced in September were still being processed when the month closed. They’ll land in October’s count, dated to whenever they actually happened.

Which is the point I keep coming back to in these posts. A quiet inbox is not evidence. The month your data surfaces has nothing to do with the month it was taken.

The passwords are back, so the advice changes

August’s roundup had a section called “this month’s leaks are about your phone, not your password”, because none of the nine entries contained one. September is different. Two of five do.

Both are hashed. Neither is plaintext. But hashed isn’t the same as safe, and the type of hash is the whole story.

Breach Hash What that means for you
LegionProxy bcrypt Slow to crack by design. A unique password here is probably fine. A reused one still isn’t.
Fanlore PBKDF2 (newer accounts) Also slow. Same advice.
Fanlore MD5 (older accounts) Fast to crack, often already cracked. Change it everywhere you used it. Today.

We’ve seen this pattern in 516 breaches that leaked passwords: how a site stored your password decides how much a breach costs you, and you had no say in it.

So, three things for September, in order of how much they matter.

First, if you ever had a Fanlore or LegionProxy account, run the email through the free check and look at the password-risk flag on the result. Then change that password anywhere it was reused. Not rotated, replaced.

Second, if you’re in the MAG or Chess.com data, your password is fine, and your inbox isn’t. Expect messages that know your username, your car, your travel dates.

Verify through a number or link you look up yourself, never one they hand you. We wrote up why a leaked phone number is worse than a leaked email on Monday, and MAG is the textbook case.

Third, if your work address is in Baxter (or MAG’s corporate side), tell IT. Someone there can watch the whole domain for free, which is a better use of their afternoon than resetting one mailbox.

On the radar: reported in September, not yet verified

The news was a lot louder than our index this month. Seventeen breach stories crossed our feed in September, against five verified additions.

These are the five I’d keep an eye on. None is in the catalog yet, and none counts toward the 13.6 million, because we only index what we can verify.

  • IDScan is the one I’d watch. The ID-checking company (think of the scanner at a venue door or a dispensary counter) confirmed on its own website that driver’s licence data was stolen from its cloud systems. A criminal lookup site claims more than 150 million US and Canadian licences; IDScan says it holds that many records, but hasn’t said how many were taken.
  • Gyazo: 23.62 million user records from the screenshot-sharing service, taken on 11 September through a flaw in its upload server. Password hashes are in there, and login session IDs too. The company has asked every user to change their password, and I wouldn’t wait for us before doing it.
  • US Defense Manpower Data Center: nearly 2.8 million living people with military ties had their names, birth dates and Social Security numbers exposed (so did 294,000 who have since died). Whoever got in had access from October 2025 until July 2026. Nine months.
  • CenterPoint Energy: the US utility told regulators that someone took customer information through one of its outward-facing systems. It hasn’t said how many customers. The person claiming the theft says 7.49 million records, partial Social Security numbers among them.
  • AdaptHealth: 4.1 million people, health and insurance information, and a way in through a contractor’s account back in June. It took until September to put a number on it.

What can you do about a breach nobody can search yet? If you’ve used any of these five, act on the company’s own notice now. Then let an alert do the waiting.

We track stories like these through xonPulse, our breach-news feed. When leaked data from any of them surfaces and is verified, it enters the index and alerts go out.

Sometimes that takes a week, as it did with MAG. LegionProxy took 180 days. Alert subscribers don’t need to know which kind they’re dealing with, because the alert arrives either way.

Since the month closed

One entry has landed in October so far, and regular readers will know the name. McKesson sat on this radar list in August’s post as a claim of 284 million records. On 2 October, it entered the index: 6,832,822 unique email addresses, with names, phone numbers, home addresses, and dates of birth.

No passwords in it. But a message that knows your date of birth and sounds like your pharmacy is hard to ignore, so if you get one, look the number up yourself before you call back.

It happened in August, so it’ll be dated to August, and it’ll count in October’s post. The backlog I mentioned is still loading, so expect a few more like it.

Check yourself, then stop checking

Ten seconds against the full index, free, no signup: xposedornot.com

Better: verify your domain or set up alerts for everyone in your org, and let October’s additions find you instead of the other way round. Every number in this post is queryable on the free API, no key needed, and every breach above has its own page in the breach directory.

And if this monthly receipt-keeping is useful to you, a star on GitHub helps others find the project. It makes our day too, which I say every month and mean every month.

FAQ

How many data breaches were added in September 2026? Five breaches entered the XposedOrNot index in September 2026, totalling 13,680,402 records: Manchester Airports Group, Chess.com, Baxter International, Fanlore and LegionProxy. Four of them happened in August 2026 and one in April 2026. No other month of 2026 has been this low so far (August had nine, July had thirteen).

Was Chess.com hacked in 2026? Not according to the available reporting. Someone scraped 7.3 million records off the public side of the platform in August 2026, so nobody got into its systems, and no passwords came out. We still index it, because 4.6 million of those rows have an email address sitting next to a username, a name, and a country.

Which September 2026 breaches included passwords? Two of the five did. Fanlore had 145,195 accounts with hashes kept as MD5 or PBKDF2, depending on how old the account was, and LegionProxy had 10,148 with bcrypt. The other three had no passwords in them at all, so if you only change one thing, make it an old Fanlore password you reused somewhere else.

Appendix: Sources and references

Get alerted when your email shows up in a new breach. Set up free breach alerts, it takes two minutes.


Check out some of our posts for you.

Discover more from Data Breach Insights

Subscribe now to keep reading and get access to the full archive.

Continue reading