Two breaches landed in the same month. Both involve places you can't really opt out of. One keeps records about your car. The other sends you a power bill. You never picked either one.
In September 2026, Florida confirmed a breach of its driver and vehicle database. Days later, CenterPoint Energy told investors that a hacker had taken customer data. Both stories are still unfolding. And the biggest numbers come from the hackers, not from the victims. Here's what's confirmed, what's only claimed, and what to do.
Florida's driver database
On September 4, 2026, Florida's Department of Highway Safety and Motor Vehicles said it had learned of a data breach by "an international cybercriminal organization." The group is ShinyHunters, an extortion gang. It went after DAVID, the state's driver and vehicle records system.
The way in was small. Florida says the attackers used the login of one Plant City Police Department employee. That login was "improperly stored on the employee's personal electronic device." ShinyHunters says it also used a password-reset flaw to reach more accounts. Florida's statement mentions only the police login.
ShinyHunters claims it took more than 200,000 driver records. Florida has not confirmed that number or said what was taken. After no ransom was paid, the group posted the files online. TechCrunch reports they include vehicle ownership records with names, addresses, and vehicle ID numbers. A smaller set reportedly holds Social Security numbers, foreign passports, and immigration papers. TechCrunch says no driver's licenses or photos were in the leak. Hackread says the files include scans of Social Security cards and licenses. The two reports don't agree on that.
One more warning about numbers. The leaked archive is reported to hold about 613,000 zip files. That doesn't mean 613,000 people. Several files can belong to one person or one car sale. Florida hasn't said how many residents are affected. If you've bought or sold a vehicle in Florida, your name and address may be in those files.
CenterPoint Energy
CenterPoint is a Houston-based utility. It serves about 7 million customers in Indiana, Minnesota, Ohio, and Texas, so this is not only a Houston story. On September 14, it told the SEC that "an unauthorized third party obtained personal information relating to a portion of the Company's customers" through one of its external-facing systems.
CenterPoint says it learned of the problem from an online post by someone claiming to hold the data. What it hasn't said: how many customers were hit, or what information was taken.
Those details come from the hacker. The post claims 7.49 million lines of data: names, phone numbers, addresses, account numbers, emails, driver's license numbers, and the last four digits of Social Security numbers. Lines are not people, though. One customer can show up more than once. Treat all of it as a claim until CenterPoint says otherwise.
The hacker also claims to have pulled the data from a public API with no limit on how many requests one visitor could make. In plain terms: a program could ask for record after record, with nothing to slow it down. CenterPoint hasn't confirmed that. It says power and gas service were not affected. Customers have already filed class-action lawsuits.
The same weak spot, twice
Neither breach reads like a movie hack. One police login sat on a personal phone. One back door on a utility's website was reportedly left open. Your data was only as safe as the weakest login or the loosest system near it. And you had no say in it. Records about your car and your power bill come with living your life.
- Freeze your credit. It's free at Equifax, Experian, and TransUnion. A name, an address, a license number, and the last four digits of an SSN can help someone pass identity checks. Here's how to freeze.
- Treat any contact that knows your details as unproven. A caller who recites your account number or address could still be a scammer. Hang up and call the number on your bill. Why this keeps working.
- Keep any notice letter. It tells you what was taken. It may also be your proof of eligibility if a settlement follows, like the Americold payout. Our guide to reading a breach letter shows what to look for.
- Watch for sign-ups you didn't start. Account confirmations, new-card emails, and texts about services you never ordered are early warnings. Don't ignore them.
Both investigations are still going, and the numbers could change. Until then, the safest move is the same one that works for every breach: lock down what's permanent, and doubt anyone who contacts you first.
Is your info in a breach like these?
Our free scan shows which known breaches contain your email and whether identity data was exposed alongside it.
Run the Free Breach Scan →