The past seven days added three distinct threats to an already crowded 2026 breach calendar, and each one lands differently for the average person. A Texas utility confirmed millions of customer records were pulled through an unsecured API. A driver's license marketplace that surfaced earlier this month kept expanding, with the FBI's investigation still active. And a widely used image-hosting service disclosed a breach touching tens of millions of accounts. None of these are theoretical. All three involve data that criminals use immediately, not eventually.

CenterPoint Energy Data Breach Exposes Utility Customer Records

CenterPoint Energy, which serves millions of electric and gas customers across Texas, Indiana, Minnesota, and Ohio, confirmed in a September 14 SEC filing that an unauthorized third party obtained personal information belonging to a portion of its customers through an external-facing system. In a filing with the U.S. Securities and Exchange Commission on September 14, 2026, CenterPoint Energy said it became aware in September of a third-party post claiming to possess customer information, and its investigation determined an unauthorized party had obtained personal information associated with a portion of CenterPoint customers.

A threat actor operating under the alias "4d722e4d656f77" separately claimed responsibility, saying the data was pulled through a poorly secured guest-facing API. The threat actor told a reporter they stole from CenterPoint Energy 7.49 million customer records that include names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers. Multiple class-action lawsuits have already been filed, with one alleging the data breach occurred between August 17 and September 1. This is a financial-data breach, not a marketing-list breach — partial SSNs and billing account numbers are usable for account takeover and synthetic identity fraud.

Driver's License Marketplace "Nexus" Keeps Growing — FBI Investigation Continues

The Nexus identity document marketplace, first reported in late August, remains an active investigation this week and continues to be the largest identity-document exposure ever tracked in North America. A new user on the Russian cybercrime forum Exploit advertised access to digital scans of identity documents on more than 170 million people in North America, with the service claiming more than 153 million driver's licenses for people in the United States and Canada. The bulk of these records are on Americans, but a search for Canadian driver's licenses returns approximately 1.1 million results, with the largest concentration from Ontario at 473,673 records.

Unlike a password, a driver's license number cannot be reset. Neither a driver's license number nor a Tax ID can be reset. The suspected source is an identity-verification vendor used by retailers, dispensaries, and financial services firms to check age and identity — meaning the exposure sits one layer removed from the businesses consumers actually trust with their ID.

Gyazo Breach Adds Millions More Records to Circulation

Separately, image-sharing platform Gyazo disclosed a breach this week affecting a large user base. Helpfeel disclosed a breach of its Gyazo image-sharing service after an attacker exploited a flaw in an upload server on September 11, exposing roughly 23.62 million user-related records and metadata tied to about 490 million images. Email addresses and account metadata from breaches like this routinely end up in breach databases used for credential-stuffing attacks against unrelated accounts that share the same password.

What Individuals Should Do This Week

  • If you are a CenterPoint Energy customer in Texas, Indiana, Minnesota, or Ohio, monitor your utility account and bank statements for unfamiliar activity and place a fraud alert with the credit bureaus.
  • Check whether your email appears in recent breach databases, and change reused passwords immediately, prioritizing email and banking logins.
  • If you have used an ID-verification service at a retailer, dispensary, or financial app in the past year, assume your driver's license image may be circulating and watch for new-account fraud notices.

What Businesses Should Do This Week

  • Audit every external-facing and guest-facing API for authentication and rate-limiting gaps — the CenterPoint incident began with exactly this weakness.
  • Review which third-party vendors hold copies of customer identity documents, and confirm retention periods and deletion policies rather than assuming compliance.
  • Treat any employee credential exposed in a breach database as compromised immediately, not after the next password rotation cycle.