Five breaches were added to the XposedOrNot index in September. Between them: 13.6 million records.
That’s the fewest additions of any month this year. August had nine, July thirteen.
And yet I wouldn’t call September quiet, because two things changed that the headline count hides. Passwords came back. And one entry wasn’t a hack at all.
Quick context if you’re new to these. I run XposedOrNot, a free, open-source service: type in an email address and it tells you which public breaches it turns up in. Behind it is a catalog of 787 breaches, 11,633,142,187 records as of the last count.
I pulled every number below from it on the morning of 5 October 2026.
The short version
- Five breaches, 13,680,402 records. Manchester Airports Group is 61% of the month on its own.
- Two of the five contain password hashes (Fanlore and LegionProxy). August had none in nine.
- Chess.com wasn’t broken into. Its 7.3 million rows were scraped from public profiles, and 4.6 million unique emails came along for the ride.
What landed in the index
Every entry is verified and searchable. Counts are records, not people. (You can turn up twice in the same breach, and I often do.)
| Breach | Happened | Records | Reached the index after | Passwords in the data? |
|---|---|---|---|---|
| Manchester Airports Group | Aug 2026 | 8,379,476 | 5 weeks | No |
| Chess.com | Aug 2026 | 4,656,591 | 8 weeks | No |
| Baxter International | Aug 2026 | 488,992 | 5 weeks | No |
| Fanlore | Aug 2026 | 145,195 | 8 weeks | Yes, hashed |
| LegionProxy | Apr 2026 | 10,148 | 26 weeks | Yes, hashed |
Four of the five happened in August. So this is really the second half of August’s story, with one straggler from April tacked on at the end. The median gap from breach to searchable was 55 days.

A few rows deserve more than a row.
Manchester Airports Group is the one to check if you’ve flown from the north of England. MAG runs Manchester, Stansted and East Midlands. The group disclosed the theft on 27 August, and the data (8.4 million email addresses with phone numbers, vehicle registrations, parking history, Fast Track and lounge bookings) was published by a group calling itself FulcrumSec. It was searchable here on 3 September, seven days after the disclosure.
Think about what a parking record gives a scammer. Your car’s registration, the dates you were away, your phone number. “We’re calling about a problem with your airport parking booking” is a sentence that lands very differently when the caller already has all three.
Chess.com is a scrape, not a break-in. Nobody got inside Chess.com’s servers, as far as the reporting goes. Someone pulled 7.3 million user records from the platform’s public-facing features over about a week in late July and early August, then gave the file away on two forums. The platform itself described it as mass scraping.
So why index it? Because 4.6 million of those rows carry an email address, and an email next to a username, a real name, and a country is exactly the kit a phishing crew wants.
Stolen or collected makes no difference to the person who gets the email. (We’ve kept the catalog entry honest about the method, though. The description says scraped.)
Baxter International is another CRM export. 7.1 million Salesforce records, 489 thousand unique email addresses with names and physical addresses, leaked after the company declined to pay. Same playbook as Questel and Sharecare in August, same group named in the reporting. If your work address is in it, this is a tell-your-IT-team breach, not a change-your-password one.
Fanlore is small, and it’s the one I’d act on first. Fanlore is the fan-culture wiki run by the Organization for Transformative Works (the AO3 people, though AO3 wasn’t touched). The OTW found the intrusion on 6 August and published a full write-up, which is more than most companies ten times their size manage. The haul was 145,195 email addresses with usernames and password hashes. Old accounts had theirs kept as MD5, newer ones as PBKDF2.
MD5 is the bit that worries me. If you made a Fanlore account years ago and used that password anywhere else, treat it as burned.
LegionProxy is the straggler. A residential proxy service, 10,148 customers, bcrypt password hashes, a breach from April. It only reached us on 28 September, 180 days after the fact. It also happens to be the 79th breach of 2026 in our catalog, the one that broke the yearly record I wrote about last week.
Why “quietest month” is the wrong headline
Here’s the number I’d put on the wall: 13, then 9, then 5. Monthly additions to the index for July, August and September.

Three straight months of decline. Tempting to read that as the world calming down. It isn’t.
Two things are going on. First, the groups that drove the summer (one name appears in five of August’s nine) publish in bursts, and September’s burst mostly landed in the news rather than as verified data. More on that in the radar section below.
Second, and I’ll be honest about this one, our own backlog. Several breaches that surfaced in September were still being processed when the month closed. They’ll land in October’s count, dated to whenever they actually happened.
Which is the point I keep coming back to in these posts. A quiet inbox is not evidence. The month your data surfaces has nothing to do with the month it was taken.
The passwords are back, so the advice changes
August’s roundup had a section called “this month’s leaks are about your phone, not your password”, because none of the nine entries contained one. September is different. Two of five do.
Both are hashed. Neither is plaintext. But hashed isn’t the same as safe, and the type of hash is the whole story.
| Breach | Hash | What that means for you |
|---|---|---|
| LegionProxy | bcrypt | Slow to crack by design. A unique password here is probably fine. A reused one still isn’t. |
| Fanlore | PBKDF2 (newer accounts) | Also slow. Same advice. |
| Fanlore | MD5 (older accounts) | Fast to crack, often already cracked. Change it everywhere you used it. Today. |
We’ve seen this pattern in 516 breaches that leaked passwords: how a site stored your password decides how much a breach costs you, and you had no say in it.
So, three things for September, in order of how much they matter.
First, if you ever had a Fanlore or LegionProxy account, run the email through the free check and look at the password-risk flag on the result. Then change that password anywhere it was reused. Not rotated, replaced.
Second, if you’re in the MAG or Chess.com data, your password is fine, and your inbox isn’t. Expect messages that know your username, your car, your travel dates.
Verify through a number or link you look up yourself, never one they hand you. We wrote up why a leaked phone number is worse than a leaked email on Monday, and MAG is the textbook case.
Third, if your work address is in Baxter (or MAG’s corporate side), tell IT. Someone there can watch the whole domain for free, which is a better use of their afternoon than resetting one mailbox.
On the radar: reported in September, not yet verified
The news was a lot louder than our index this month. Seventeen breach stories crossed our feed in September, against five verified additions.
These are the five I’d keep an eye on. None is in the catalog yet, and none counts toward the 13.6 million, because we only index what we can verify.
- IDScan is the one I’d watch. The ID-checking company (think of the scanner at a venue door or a dispensary counter) confirmed on its own website that driver’s licence data was stolen from its cloud systems. A criminal lookup site claims more than 150 million US and Canadian licences; IDScan says it holds that many records, but hasn’t said how many were taken.
- Gyazo: 23.62 million user records from the screenshot-sharing service, taken on 11 September through a flaw in its upload server. Password hashes are in there, and login session IDs too. The company has asked every user to change their password, and I wouldn’t wait for us before doing it.
- US Defense Manpower Data Center: nearly 2.8 million living people with military ties had their names, birth dates and Social Security numbers exposed (so did 294,000 who have since died). Whoever got in had access from October 2025 until July 2026. Nine months.
- CenterPoint Energy: the US utility told regulators that someone took customer information through one of its outward-facing systems. It hasn’t said how many customers. The person claiming the theft says 7.49 million records, partial Social Security numbers among them.
- AdaptHealth: 4.1 million people, health and insurance information, and a way in through a contractor’s account back in June. It took until September to put a number on it.
What can you do about a breach nobody can search yet? If you’ve used any of these five, act on the company’s own notice now. Then let an alert do the waiting.
We track stories like these through xonPulse, our breach-news feed. When leaked data from any of them surfaces and is verified, it enters the index and alerts go out.
Sometimes that takes a week, as it did with MAG. LegionProxy took 180 days. Alert subscribers don’t need to know which kind they’re dealing with, because the alert arrives either way.
Since the month closed
One entry has landed in October so far, and regular readers will know the name. McKesson sat on this radar list in August’s post as a claim of 284 million records. On 2 October, it entered the index: 6,832,822 unique email addresses, with names, phone numbers, home addresses, and dates of birth.
No passwords in it. But a message that knows your date of birth and sounds like your pharmacy is hard to ignore, so if you get one, look the number up yourself before you call back.
It happened in August, so it’ll be dated to August, and it’ll count in October’s post. The backlog I mentioned is still loading, so expect a few more like it.
Check yourself, then stop checking
Ten seconds against the full index, free, no signup: xposedornot.com
Better: verify your domain or set up alerts for everyone in your org, and let October’s additions find you instead of the other way round. Every number in this post is queryable on the free API, no key needed, and every breach above has its own page in the breach directory.
And if this monthly receipt-keeping is useful to you, a star on GitHub helps others find the project. It makes our day too, which I say every month and mean every month.
FAQ
How many data breaches were added in September 2026? Five breaches entered the XposedOrNot index in September 2026, totalling 13,680,402 records: Manchester Airports Group, Chess.com, Baxter International, Fanlore and LegionProxy. Four of them happened in August 2026 and one in April 2026. No other month of 2026 has been this low so far (August had nine, July had thirteen).
Was Chess.com hacked in 2026? Not according to the available reporting. Someone scraped 7.3 million records off the public side of the platform in August 2026, so nobody got into its systems, and no passwords came out. We still index it, because 4.6 million of those rows have an email address sitting next to a username, a name, and a country.
Which September 2026 breaches included passwords? Two of the five did. Fanlore had 145,195 accounts with hashes kept as MD5 or PBKDF2, depending on how old the account was, and LegionProxy had 10,148 with bcrypt. The other three had no passwords in them at all, so if you only change one thing, make it an old Fanlore password you reused somewhere else.
Appendix: Sources and references
- All 5 September additions with counts and dates: our public catalog; per-entry lookup on the breaches endpoint at api.xposedornot.com/v1/breaches (fields breachID, breachedDate, addedDate, exposedRecords, exposedData, passwordRisk), re-pulled 2026-10-05, addedDate filter 2026-09
- Lag figures: computed from each entry’s breachedDate (month granularity, counted from the 1st) vs addedDate; MAG 33 days, Baxter 34, Fanlore 55, Chess.com 57, LegionProxy 180; median 55 days
- Monthly additions for 2026 (chart): same endpoint, addedDate grouped by month, re-pulled 2026-10-05
- Manchester Airports Group: disclosure 27 August 2026; data published by FulcrumSec; reporting via BleepingComputer
- Chess.com: scraped records posted August 2026; reporting via Hackread and Teiss (platform statement: mass scraping, not a breach)
- Baxter International: unauthorised activity identified 13 August 2026, 7.1 million Salesforce records published 19 August; reporting via HealthcareInfoSecurity
- Fanlore: the OTW’s own security incident write-up (intrusion found 6 August 2026, MD5 and PBKDF2 hashes, AO3 unaffected)
- LegionProxy: breach dated April 2026, 10,148 records; no first-party disclosure located as of 2026-10-05
- On-the-radar items (xonPulse entries dated September 2026, 17 in total, five chosen; all five checked absent from the catalog by breachID and domain on 2026-10-05): IDScan via TechCrunch (10 September 2026); Gyazo via BleepingComputer (18 September); Defense Manpower Data Center via Federal News Network (28 September); CenterPoint Energy via BleepingComputer (15 September); AdaptHealth via BleepingComputer (9 September)
- McKesson: catalog entry added 2026-10-02, breachedDate Aug 2026, 6,832,822 records; the 284 million figure is the attackers’ claim as reported in the August 2026 roundup
- Previous roundups: August 2026, July 2026
- Related: Data breaches by year: 2026 sets a new record, 516 breaches leaked passwords, 56% stored them badly, Phone number leaked? Why it’s worse than a leaked email, Monitor every domain you own for breaches, Breach alerts for your whole org, free, How big is a data breach?
Get alerted when your email shows up in a new breach. Set up free breach alerts, it takes two minutes.
Check out some of our posts for you.
- September 2026 Breach Roundup: 13.6 Million Records, and the Passwords Are Back
- MCP Makes Your AI Assistant Breach-Aware and Powerful
- Change Your Email After a Breach? Only in These 3 Cases
- Data Breaches by Year: 2026 Sets a New Record in Our Catalog
- Phone Number Leaked? Why It’s Worse Than a Leaked Email
- How Big Is a Data Breach?





