Global data breaches exposed 320 mn people's info since September: Report
Among the major incidents, digital scans of 153 million US driver's licences were reportedly leaked, with the records allegedly being offered for sale on a Russian cybercrime forum on the dark web
)
The increase in data breaches comes as organisations face a broader rise in cyber threats. (Image: Shutterstock)
Listen to This Article
Data breaches worldwide have exposed the personal information of at least 320 million people since September, according to a report by Nikkei Asia. The findings highlight the growing scale of cyberattacks, with criminals increasingly focusing on stealing personal information rather than disrupting company systems or demanding ransom payments.
The trend comes as organisations worldwide face a rise in cyberattacks. According to Check Point Research's September 2026 Cyber Threat Landscape report, organisations faced an average of 2,803 cyberattacks a week in September, up 48 per cent from a year earlier. Meanwhile, Microsoft's Digital Defense Report 2026 found that 63 per cent of intrusions involved data theft.
India, meanwhile, remains among the five Asia-Pacific (APAC) countries most targeted by advanced persistent threats (APTs), according to cybersecurity firm Kaspersky's Global Research and Analysis Team (GReAT). Security firms have also flagged the growing use of artificial intelligence (AI) to automate different stages of cyberattacks.
Data breaches affect millions worldwide
Nikkei Asia examined publicly disclosed data breaches worldwide involving at least 100,000 victims. Its analysis covered company and government announcements, information from research firms and claims made by attackers, provided the affected companies had acknowledged the breaches.
Among the major incidents, digital scans of 153 million US driver's licences were reportedly leaked from identity verification company IDScan.net. An American cybersecurity blog reported that the records were being offered for sale on a Russian cybercrime forum on the dark web.
Also Read
IDScan.net later said an unauthorised third party had accessed part of its systems between April 4 and September 2.
Dodo Brands, a Kazakhstan-based multinational operator of pizza chains, also suffered a cyberattack in which data belonging to 68 million customers was stolen. The company reported the incident to authorities in Russia and Turkey in late September, the news report said.
Japan accounted for 20 of the 35 breaches covered by Nikkei, affecting a total of 57 million people. These included incidents involving a barbecue restaurant chain operator, which saw 10.78 million customers affected, and a car-sharing service provider, where 6.6 million customers were hit.
The scale of these incidents comes against the backdrop of a large number of data breach notifications in the US. The Identity Theft Resource Center, a US-based non-profit organisation, estimated that 471.2 million data breach victim notices were issued in the first six months of 2026.
Global cyberattacks rise 48% in September
The increase in data breaches comes as organisations face a broader rise in cyber threats. Check Point Research found that organisations faced an average of 2,803 cyberattacks a week in September 2026, a 16 per cent increase from August and a 48 per cent rise from September 2025.
The education sector was the most targeted, facing an average of 6,656 attacks a week per organisation, up 59 per cent from a year earlier. Telecommunications and government followed, with 3,483 and 3,443 weekly attacks per organisation, respectively.
The report also recorded 824 ransomware attacks in September, 53 per cent more than in the same month last year.
Phishing attacks also became more frequent. One in every 91 emails was classified as phishing in September, compared with one in every 112 in August. Phishing involves fraudulent messages designed to trick people into revealing sensitive information, clicking malicious links or downloading harmful files.
AI gives cybercriminals new tools
The nature of cyberattacks also appears to be changing, with AI potentially helping criminals carry out operations faster and on a larger scale.
South Korean President Lee Jae Myung on Tuesday said AI may have played a role in a recent series of cyberattacks targeting financial institutions in the country. The attacks exposed records belonging to at least 65,000 customers. Korea Electric Power Co. and universities have also reported similar incidents, according to Nikkei Asia.
The increasing availability of powerful AI models could further lower the barriers to carrying out sophisticated cyberattacks. Nikkei cited an assessment by the US Centre for Advancing Innovation and Standards for Super Intelligence, which said China's Z.ai's GLM-5.3 model, released in August, showed performance comparable to Anthropic's Mythos Preview model, released in April.
A cybersecurity engineer at a technology company affected by a data breach described a continuous stream of attacks that appeared faster than human operators could manage. However, the attacks lacked the regular pattern typically associated with automated tools.
This showed that attackers may be combining AI capabilities with other techniques to make their operations faster and less predictable.
Microsoft's Digital Defense Report 2026 also highlighted the growing importance of data theft in cyber incidents. The company found that 63 per cent of intrusions involved data theft and detected more than 46 million business email impersonation attacks over the last 12 months.
Business email impersonation involves attackers posing as legitimate individuals or organisations to trick recipients into sharing information or transferring money.
AI can also help security teams identify vulnerabilities and fix weaknesses in their systems. However, defenders must detect and verify threats while keeping their systems operational, creating a continuing challenge as attackers develop new methods.
India among five APAC countries targeted by advanced threats
India is among the five Asia-Pacific countries most targeted by advanced persistent threats, according to Kaspersky's GReAT. The other four are China, Myanmar, Pakistan and Vietnam. Kaspersky said it monitors more than 900 APT groups worldwide.
Kaspersky blocked 75 million attacks from online resources across the Asia-Pacific region in the first half of 2026. Between January and June, it also blocked 3.4 million backdoor attacks, 2.4 million password-stealer attacks and 250,000 ransomware incidents.
According to Kaspersky GReAT, cybercriminals are increasingly using AI at different stages of their operations. These include automating reconnaissance, speeding up the development of malicious software and carrying out attacks on a larger scale. Reconnaissance involves gathering information about potential targets, including their systems, networks and security weaknesses. Automating this process can help attackers identify vulnerable systems more quickly.
APTs remain a major cybersecurity concern
Advanced persistent threats remain a significant part of the global cybersecurity landscape. Kaspersky said APTs accounted for 24 per cent of the most serious security incidents globally in 2025. Social engineering accounted for 15 per cent, followed by malware at 12 per cent.
An APT is a targeted cyber campaign in which attackers gain unauthorised access to a network and remain hidden for an extended period. Such attacks can be used for cyber espionage, stealing confidential information or pursuing longer-term strategic objectives.
Unlike attacks designed to cause immediate disruption, APT campaigns may involve quietly monitoring a target's systems and extracting information over time. Their prolonged and covert nature can make them difficult to detect.
More From This Section
Topics : Cyberattacks Cyber threat data leak BS Web Reports
Don't miss the most important news and views of the day. Get them on our Telegram channel
First Published: Oct 09 2026 | 12:39 PM IST
