September 2026 retail data breach news centers on notices from Catalyst Brands and See's Candies, plus an expanded ShipMonk-related disclosure from Trezor. The key takeaway is that employee records, customer files, and old fulfillment data can remain exposed long after the initial intrusion—or beyond an expected deletion date. These incidents create different risks. Catalyst Brands disclosed sensitive identity and account data, See's Candies reported stolen files appearing on the dark web, and Trezor warned of targeted scams and physical-security concerns.
Table of Contents
- Catalyst Brands disclosed an HR and payroll breach
- See's Candies reported encryption and file theft
- Trezor expanded the ShipMonk incident population
- What affected readers should do now
- The September security advisory is separate from consumer breaches
Catalyst Brands disclosed an HR and payroll breach
Catalyst Brands reported unauthorized access to a third-party human resources and payroll server around May 20, 2026. The company determined on august 5 that the intruder had obtained personal information, according to its September 4 consumer notice. The affected information varied by person. It could include Social Security numbers, passport or driver's-license details, financial-account information, login credentials, and digital signatures.
This combination raises more than one concern. Identity documents and Social Security numbers can support impersonation, while login and financial details can expose accounts. A copied digital signature may make a fraudulent request appear more credible. Catalyst Brands offered two years of Experian identity protection and credit monitoring. Recipients should enroll before any deadline stated in their individual letter and preserve the notice for reference.
See's Candies reported encryption and file theft
See's Candies said an intruder accessed parts of its network from April 11 through April 13. The intruder encrypted files, acquired some files, and later made at least some of them available on the dark web, according to the company's notice filed September 2 with the California Department of Justice. The notice said See's Candies had no evidence of resulting identity theft or fraud. That statement does not establish that misuse cannot occur later, especially when copied files have been published.
A significant limitation remains: the public notice template leaves the affected data categories blank. Readers therefore cannot determine from that template alone which specific information was exposed. Each recipient should rely on the personalized notice rather than assume another person's data categories match their own. See's Candies offered affected consumers 12 months of Experian IdentityWorks. Recipients should also treat unexpected messages referencing the company or the incident as potentially deceptive.
Trezor expanded the ShipMonk incident population
Trezor's September 4 update added roughly 67,000 U.S. customers to the population affected by ShipMonk's breach. The exposed records covered orders placed from November 2019 through August 2021 and included names, email addresses, phone numbers, shipping addresses, and order numbers, according to Trezor's incident update. Trezor said ShipMonk had provided written assurances that the old order data was deleted, but the information remained in ShipMonk's systems.
This makes data-retention controls a central issue: a vendor's deletion assurance did not prevent legacy customer records from being exposed. Trezor said its systems and hardware wallets were not compromised. The incident therefore does not indicate access to the wallets themselves, but order details can help criminals tailor phishing emails, fraudulent calls, or letters. A shipping address tied to a hardware-wallet order also creates a physical-security concern. Affected buyers should be cautious about messages that reference authentic order details, because accuracy does not prove that the sender is legitimate.
What affected readers should do now
Start with the exact notice you received. Confirm the company named, the affected data categories, the incident dates, and the enrollment period for any monitoring service.
Then prioritize protections based on the exposed information: Trezor customers should never treat knowledge of an old order number or shipping address as proof of identity. Catalyst Brands recipients should focus on the particular data listed in their letters, while See's Candies recipients should not infer their exposed fields from the incomplete public template.
- Enroll in offered identity or credit monitoring through the instructions in the verified notice.
- Change any exposed password and any other account password that reused it.
- Contact the relevant financial institution if the notice identifies financial-account data.
- Watch for calls, emails, or letters that use real order or employment details to create urgency.
- Independently find official contact information instead of using links or phone numbers in an unexpected message.
The September security advisory is separate from consumer breaches
CISA's September 3 advisory concerns OPC UA LocalDiscoveryServer, software used in food-and-agriculture and other industrial environments. It is an industrial cybersecurity issue, not a notice that consumer retail data was exposed. The reported vulnerability requires local privileged installation access, and CISA identified no known public exploitation.
Operators should update to version 1.04.420 or later, as directed in CISA's September 3 advisory. This distinction matters when reading breach roundups. A security advisory identifies a weakness and remediation step; a breach notice reports unauthorized access or exposure. Organizations running the affected software should update it, while consumers do not need to treat this advisory as evidence that their retail records were stolen.
You Might Also Like
- What Is New With Government Data Breach News in September 2026? Latest breach notices and security advisories and Key Takeaways
- What Is New With Healthcare Data Breach News in August 2026? Latest breach notices and security advisories and Key Takeaways
- What Is New With Financial Sector Data Breach News in August 2026? Latest breach notices and security advisories and Key Takeaways