DATA FUSION · FAILURE MODES

When data systems fail.

Connected data systems are useful because they make information easier to collect, correlate, retrieve, and share. These documented cases show the other side of that utility: when infrastructure, credentials, or disclosure controls fail, the same efficiency can increase the scale of exposure.

SCOPE + EVIDENCE RULE

This is a selected set of documented failure modes, not a catalogue of every breach. Some cases involve compulsory or effectively unavoidable records; others show what can happen when privileged access, connected infrastructure, or trusted disclosure mechanisms are compromised.

Claims are not confirmations. NoRec separates an organization's acknowledgement, independently verified reporting, regulator findings, and claims made by attackers. A number advertised on a leak site is not presented as a confirmed victim count unless the evidence supports it.

DATA BREACHES

Data was taken from systems entrusted with it.

FEDERAL · PERSONNEL / APPLICANT DATA · 2026

FBIJobs.gov

CONFIRMED PORTAL COMPROMISE · SCOPE DEVELOPING

The FBI confirmed a compromise of the FBIJobs.gov portal and is investigating potential impact to employee personally identifiable information. The Bureau says the point of breach—its own enterprise or a third party—has not yet been determined.

Custodian / system
FBIJobs.gov and supporting providers
Official status
Compromise acknowledged; investigation ongoing
Independently checked sample
Reuters verified portions of a roughly 5,000-person sample
Attacker claim
2–3 TB; not confirmed by the FBI
Last reviewed
September 29, 2026

On September 23, the FBI said it was aware of a cybercriminal group claiming compromise of FBIJobs.gov and alleged impact to FBI employee PII. The Bureau explicitly said it had not yet determined whether the breach point was a third party or the FBI enterprise.

Reuters subsequently reported on a sample containing information about current and former personnel and independently corroborated portions of that sample. That supports treating some exposed material as genuine; it does not validate every field or the attackers' claimed multi-terabyte total.

What remains unknown: the final affected population, complete data categories, total volume, breach path, and how much material came from FBI infrastructure versus systems operated by supporting providers.
Sources + evidence boundary

IDENTITY VERIFICATION · GOVERNMENT IDs · 2026

IDScan.net

DOCUMENTED BREACH

IDScan.net says an unauthorized third party may have accessed or copied customer information stored in accounts on its cloud—including names and driver's-license or other government-issued identification numbers.

System
IDScan.net cloud customer accounts
Company notice
September 4, 2026
Confirmed possible data types
Names and driver's-license / government-ID numbers
Nexus marketplace claim
153M+ driver's-license records; not a confirmed unique-person count
Last reviewed
September 29, 2026

The company said it received information around September 1 indicating possible unauthorized access and later determined that an unauthorized party may have accessed or copied customer information stored in its cloud. This is especially relevant to involuntary data custody because the person presenting an ID may know the business scanning it while never forming a direct relationship with the verification provider behind the transaction.

Separate reporting connected sampled identity documents offered through a service called Nexus to IDScan.net workflows. Nexus advertised more than 153 million U.S. and Canadian driver's-license records, but that marketplace figure should not be treated as IDScan.net's confirmed affected-person count.

What remains unknown: the final unique-person count, how the Nexus inventory maps to the confirmed IDScan.net incident, which customers contributed which records, and the complete set of fields or document images obtained.
Sources + evidence boundary

HISTORICAL CASE STUDY · CONSUMER REPORTING · 2017

Equifax

HISTORICALLY DOCUMENTED

The 2017 Equifax breach exposed personal information belonging to approximately 147 million people. It remains a useful example because a consumer does not need to open an Equifax account for Equifax to maintain a file about them.

Affected
Approximately 147 million people
Exposed at scale
Names, dates of birth, SSNs, addresses and other personal information
Security finding
FTC alleged failures including patching, segmentation and intrusion detection
Why it matters here
Consumer reporting is largely indirect data collection
Last reviewed
September 29, 2026

The FTC alleged that Equifax failed to patch a critical vulnerability after being alerted to it, and that attackers subsequently reached large amounts of consumer PII. The settlement described approximately 147 million affected people, including roughly 145.5 million Social Security numbers.

The CFPB describes Equifax as collecting and organizing data on most adult Americans to produce reports sold for decisions involving loans, jobs, housing and other products. Credit-reporting information can be furnished by lenders and other businesses; a consumer does not need to deliberately create an Equifax account for a credit file to exist.

The database you never signed up for: ordinary participation in credit, lending and housing markets can create records at consumer-reporting companies with which the individual never established a conventional customer relationship.
Sources + evidence boundary

TELECOMMUNICATIONS · LAWFUL-ACCESS DATA · 2024

Salt Typhoon

DOCUMENTED COMPROMISE

The FBI and CISA confirmed that PRC-affiliated actors compromised multiple telecommunications companies, stealing call-record data and copying some information that was subject to U.S. law-enforcement requests pursuant to court orders.

Targets
Multiple telecommunications companies
Confirmed exposure
Customer call records, limited private communications, and select court-order-related information
Attributed by
FBI and CISA to PRC-affiliated actors
Last reviewed
September 29, 2026

The November 2024 FBI/CISA statement described a broad cyber-espionage campaign against commercial telecommunications infrastructure. The agencies said the intrusion enabled theft of customer call-record data, compromise of private communications belonging to a limited number of primarily government or political targets, and copying of certain information subject to U.S. law-enforcement court orders.

NoRec does not describe this more broadly as proof that every lawful-intercept mechanism was compromised. The documented point is narrower: information associated with lawful government requests was among the material copied during a major compromise of telecommunications providers.

Sources + evidence boundary

ACCESS + DISCLOSURE VULNERABILITIES

Sometimes, you don't even need to hack.

Humans make mistakes. Systems make mistakes. Stolen credentials, compromised accounts, forged requests, social engineering, and ordinary human error can expose the same information. The vulnerability isn't always the database itself. Sometimes it's the trust surrounding access to it.

FLORIDA · DRIVER RECORDS · 2026

Florida DAVID

DOCUMENTED ACCESS FAILURE

Florida confirmed unauthorized access to its Driver And Vehicle Information Database through a compromised law-enforcement credential. The officially confirmed scale remains undisclosed.

Custodian
Florida Department of Highway Safety and Motor Vehicles
Access path
Compromised Plant City Police Department user credential
Official affected-record count
Not disclosed
Reported attacker claim
200,000+ records; not confirmed by Florida
Last reviewed
September 29, 2026

Florida said it learned of the incident on September 4, 2026 and determined that access occurred through credentials belonging to a Plant City Police Department employee that had been improperly stored on the employee's personal electronic device. The state said the incident was mitigated and its investigation continued.

This did not require defeating DAVID itself: valid credentials became the access path. The important boundary is scale: reporting on the incident has described an attacker claim of more than 200,000 records, but Florida has not publicly confirmed that number. NoRec therefore treats the breach and credential path as documented while leaving the total number of affected records unresolved.

What remains unknown: the authoritative number of records accessed or copied, the complete fields exposed, and whether additional access paths existed.
Sources + evidence boundary

STOLEN POLICE ACCESS · IMPERSONATION · 2022–2025

ViLE: privileged access became an attack surface.

DOCUMENTED · CONVICTIONS

Two ViLE members used a law-enforcement officer's stolen password to access a federal intelligence-sharing portal. One also used a compromised foreign police email account to impersonate law enforcement and obtain subscriber information from a U.S. social platform.

Failure modes
Stolen police credentials; compromised police email; fraudulent emergency requests
Portal contents
Nonpublic seizure records and law-enforcement intelligence reports
Outcome
Both defendants pleaded guilty and received federal prison sentences
Sentences
27 months and 25 months
Last reviewed
September 29, 2026

DOJ says Sagar Steven Singh and Nicholas Ceraolo used a police officer's stolen password to enter a nonpublic federal portal used to share intelligence with state and local law enforcement. The portal exposed detailed nonpublic seizure records and intelligence reports, and information obtained through it was later used to threaten victims.

Ceraolo also accessed a Bangladeshi police official's email account and used it to pose as law enforcement when requesting information from U.S. online services. In one documented instance, a social platform supplied a subscriber's address, email address, and telephone number. The case therefore shows both sides of the same trust problem: possession of privileged credentials can open government systems, while the appearance of official authority can open private disclosure channels.

Primary sources

LAW-ENFORCEMENT IMPERSONATION · EMERGENCY DATA REQUEST

A request that looked official was enough.

DOCUMENTED DISCLOSURE FAILURE

WIRED documented a case in which a fraudulent emergency request impersonating the Jacksonville Sheriff's Office was sent to Charter Communications. The target's information was returned in roughly 20 minutes.

Failure mode
Fraudulent emergency law-enforcement request
Impersonated agency
Jacksonville Sheriff's Office
Recipient
Charter Communications
Reported response time
About 20 minutes
Last reviewed
September 29, 2026

This was not described as an attacker breaking through Charter's perimeter and extracting a database. The disclosure mechanism itself was targeted: the requester presented as law enforcement and used the emergency-request process to obtain information about another person.

The broader lesson is different from a conventional breach. A system can be technically functioning while identity verification, human review, or institutional trust fails. Privileged disclosure channels therefore belong in the threat model alongside software vulnerabilities and stolen passwords.

Source + evidence boundary

MORE BREACH RESOURCES

Want to dig deeper?

These examples are only a small selection of documented incidents. For broader and more frequently updated reporting, these public resources track data breaches and compromises in greater detail.

THE COMMON THREAD

Collection creates a consequence before anyone attacks it.

These incidents have different causes: compromised infrastructure, stolen credentials, trusted-access failures, third-party custody, and fraudulent disclosure requests. They should not be collapsed into one technical category. What they share is simpler: once sensitive information is accumulated, every system, credential, contractor, employee, disclosure process, export and retained copy becomes another place where security has to work.

NoRec will add cases selectively. The goal is not the largest breach counter on the internet; it is a documented record of failures that help explain the consequences of collecting identity and surveillance data in the first place.