Data-Breach Round: Revolut, CenterPoint 7.49M, Premier Medical 280k, and Florida DMV/ShinyHunters

Four breach disclosures in one week: a fintech tricked by a fake government request, a utility with 7.49 million records claimed, a New York clinic notifying 280,000 patients, and Florida DMV data dumped by ShinyHunters.

Share
Cut-paper collage on navy: four torn-paper record cards for a bank, utility, clinic and DMV, with a red diagonal slash across the fourth.

Between September 12 and 16, 2026, four organizations in four different sectors disclosed data incidents, and the through line is not a shared piece of malware. In each case the data left through a side door: a trusted request channel, an exposed external system, or a person with legitimate access. British fintech Revolut confirmed it handed customer records to someone impersonating a government agency. Houston utility CenterPoint Energy confirmed an intrusion after a hacker claimed 7.49 million customer records. New York's Premier Medical Group is notifying more than 280,000 patients. And the ShinyHunters group published files from Florida's motor vehicle database after the state declined to pay.

This is a defender-oriented round, so for each disclosure the useful split is the same: what the organization actually confirmed, what a claimant merely asserts, and what a person in the affected pool should do now. None of these stories rewards attention to attacker technique. All four reward attention to where the trust boundary sat.

The Week’s Four Disclosures
What each organization confirmed, the scale in play, and the one move for people in each pool. September 12 to 16, 2026.
Revolut · UK Fintech
Confirmed: released customer data to an unauthorized party that used a legitimate government email domain to send fraudulent requests. A “limited” number of customers, count undisclosed. Do: treat any unsolicited “verification” contact as suspect; watch for impersonation citing your real ID details.
CenterPoint Energy · US Utility
Confirmed: an intrusion via an external system. The 7.49 million-record count and field list are the hacker’s claim, not the company’s. Claimed data includes driver’s license numbers and the last four SSN digits. Do: freeze credit; monitor billing and financial accounts.
Premier Medical Group · Healthcare
Confirmed: 282,075 individuals reported to HHS. June 2026 intrusion exposed names, contact details, diagnoses, medication and health-insurance information. Do: check provider and insurer statements for services you did not receive; report discrepancies.
Florida FLHSMV · State DMV
Confirmed: a breach of the DAVID database, tied to a police officer’s credentials stored on a personal device. ShinyHunters published the files after a refused ransom. Do: Floridians should watch for vehicle and address-based fraud; the SSN and immigration-document subset warrants a credit freeze.
Sources: Revolut breach via TechCrunch; CenterPoint via Help Net Security and the company’s SEC Form 8-K; Premier Medical via SecurityWeek and the HHS breach portal; Florida FLHSMV via TechCrunch and the agency statement. Summary: The CyberSignal.

The Revolut Fake-Government-Request Angle

Revolut's breach did not require breaking into anything. The company confirmed that an unauthorized party used a legitimate government agency email domain to submit fraudulent requests for customer information, and that Revolut released the data before catching the scam.

"Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information," a spokesperson told TechCrunch. The exposed material was substantial: identity and contact details including dates of birth, postal and email addresses and phone numbers, plus copies of identity documents including passports and driver's licenses. It may also have included verification selfies, account statements and transaction histories, per the customer notification TechCrunch reviewed.

Revolut, which reports more than 80 million customers globally, said a "limited" number of people were affected but did not disclose a figure, did not name the government agency whose domain was abused, and did not say whether the incident was limited to one market. It said it blocked the sender's email address after discovering the scam and alerted the relevant agency, law enforcement and regulators, adding that "Revolut systems and customer funds are unaffected." Crypto security researcher ZachXBT, who first surfaced the notification, said the incident appeared to target high-net-worth users.

The reusable point here, offered as assessment rather than reporting, is that the control that failed is request verification, not a firewall. An organization that will release customer records on the strength of an inbound email from an official-looking domain has a process gap, and email filtering does nothing about it. For affected customers, the practical risk is that the exposed documents are exactly what is used to pass identity checks elsewhere, so any inbound "account review" or "verification" contact that cites real details should be treated as an impersonation attempt until proven otherwise.

The CenterPoint 7.49M Utility Breach

CenterPoint Energy confirmed an intrusion into customer data through an external system, but the headline 7.49 million figure is the hacker's claim, not the company's count. That distinction is the whole story for anyone deciding how alarmed to be.

CenterPoint is a Houston-based utility serving roughly 7 million electricity and natural gas customers across Indiana, Minnesota, Ohio and Texas. A hacker posting under the alias "4d722e4d656f77" claimed to have pulled 7.49 million lines of customer data through an application programming interface that, in the poster's telling, had no web application firewall, no rate limiting, no certificate checks and no authentication token, according to Help Net Security. The claimed fields include customer names, phone numbers, service and billing addresses, account numbers, premise IDs, billing amounts, due dates, autopay and paperless status, rate class, email addresses, driver's license numbers, and the last four digits of Social Security numbers.

In an SEC Form 8-K filed on September 14, CenterPoint confirmed it became aware of an online post by a third party claiming to hold a data set containing customer information, and said it is working with outside experts to determine the scope. The filing states that "The Company's delivery of electric and gas services has not been impacted and remains operational and undisrupted," and that the company intends to notify affected customers and regulators as required by law. Local reporting notes the company already faces several class action suits over the alleged breach.

Confidence flag: the record count and the field list both originate with the attacker's post. CenterPoint has confirmed an incident and an external-system access path but has not confirmed the number of records or the categories exposed. That said, the claimed data set fits the profile of a utility customer database, and the presence of driver's license numbers and partial SSNs in the claim is reason enough for CenterPoint customers to place a credit freeze, watch financial accounts, and scrutinize billing statements rather than wait for the confirmed count.

The Premier Medical Group 280k Healthcare Breach

Premier Medical Group is notifying more than 280,000 patients that files containing their names, contact details, diagnoses and health insurance information were accessed in a June 2026 intrusion. This is the most fully confirmed of the four, because the numbers come from the provider and a regulator rather than from an attacker.

Premier Medical Group (PMG) is a New York provider delivering care across cardiology, dermatology, gastroenterology, neurology, plastic surgery, gynecology and internal medicine at multiple Hudson Valley locations. The provider said some of its systems were disrupted in June, and its investigation determined attackers accessed certain files on June 14. The compromised data includes names, contact information, dates of birth, treatment and diagnostic details, medication information, health insurance information, dates of service, provider names and internal patient identification numbers, per SecurityWeek. PMG reported to the US Department of Health and Human Services that 282,075 individuals were affected, and the incident now appears on the HHS breach portal.

PMG has not said how the attack happened or who was behind it, and no known ransomware or extortion group has claimed responsibility. The provider's own guidance to patients is the right one to repeat: "We recommend that patients review the statements they receive from their healthcare providers and health insurance plan. If they see any services that were not received, patients should contact their provider or health plan immediately." The specific hazard with health records is medical identity theft and insurance fraud, which surfaces in provider and insurer statements rather than in bank alerts, so that is where affected patients should be looking.

The Florida DMV and ShinyHunters Angle

ShinyHunters published hundreds of thousands of files from Florida's motor vehicle database after the state declined to pay a ransom, the group said. The published data is real, and the entry point is the part defenders should sit with.

Florida's motor vehicle agency, the FLHSMV, confirmed a breach of its database known as DAVID in a September 11 statement, after attackers obtained a police officer's credentials that were stored on a personal device, according to TechCrunch. The group said it posted the data because "the victim did not pay a ransom or cooperate and comply" with its demands. From a copy of the stolen data TechCrunch reviewed, the set contained hundreds of thousands of certificates of vehicle ownership with owners' names, buyer and seller addresses, and vehicle identification numbers. A smaller number of files included Social Security numbers and government documents such as non-US passports and immigration papers, though the set did not appear to contain driver's licenses or photos.

That leak arrived the same month that identity-verification company IDScan confirmed a separate breach of more than 150 million driver's license images, which is why driver data is the throughline across so much of this week. The Florida root cause is the instructive one: a single set of law-enforcement credentials, kept off managed devices, opened a state database. The defensive reading is that privileged access to a government record system should carry phishing-resistant authentication and should not be reachable from an unmanaged personal device at all. For Floridians whose vehicle records may sit in the set, the immediate concern is address and vehicle-based fraud, and the smaller SSN and immigration-document subset is higher risk and warrants a credit freeze.

Continuation Context: The ShinyHunters Thread

Two of these disclosures extend a thread this desk has been tracking. ShinyHunters is the same group behind the McKesson healthcare-distribution breach we covered when the company confirmed an incident while the 284 million figure stayed the group's claim, and the Florida leak lands in the same run of driver and patient-data exposure as the healthcare cloud compromise at AdaptHealth. The pattern across all of them is consistent: the notifying entity's confirmed numbers arrive late and quiet, while the claimant's numbers arrive first and loud. CenterPoint this week is the same shape, with 7.49 million as an attacker's line and no confirmed count from the company.

For anyone trying to work out when these organizations must tell you, and on what clock, our guide to how data breach notification laws work lays out the timelines that govern the letters now going into the mail, and why a healthcare provider like Premier Medical reports to HHS while a utility like CenterPoint answers to state regulators.

What Affected People Should Do

The single most useful step differs by pool, but a few actions apply across all four disclosures.

  • Freeze your credit. This matters most for the CenterPoint and Florida pools, where driver's license numbers, partial Social Security numbers, or full SSNs are in play. A freeze is free and blocks new-account fraud, which is the main downstream use of this data.
  • Set breach monitoring. Register your email and phone with Have I Been Pwned so you are alerted if any of these data sets surface there, and turn on the fraud alerts your bank and card issuers offer.
  • Scrutinize the right statements. Healthcare patients from Premier Medical should watch provider and insurer statements for care they did not receive. CenterPoint customers should watch utility billing and financial accounts. The fraud shows up in different places for different pools.
  • Treat inbound "verification" contact as suspect. The Revolut case shows how exposed ID documents get reused. Do not confirm details to anyone who contacts you first, and reach your provider through a number or app you already trust rather than one supplied in the message.

Open Questions

Several things are not settled, and it is worth being explicit about which claims are still soft. CenterPoint has not confirmed the 7.49 million record count or the field list, both of which remain the attacker's assertion. It is not established whether Florida is negotiating with ShinyHunters, only that the state confirmed the breach and the group says it published after a refused ransom. Revolut has not said what law enforcement action, if any, will follow against the party that abused the government email domain, and it has not named the agency involved. Premier Medical has not disclosed how the intrusion happened or who was responsible, and no group has claimed it.

The honest summary is that four different organizations, in four different sectors, lost data through a trusted channel or an external system in a single week, and in three of the four the confirmed scope still trails the claim. We will update this piece as those confirmed figures arrive.

Primary Documents