PrivacySignal
Breach

Broken Promises of Anonymity: Four Months Later, Still No Transparency. Now We’re Seeking Accountability.

DataBreaches.net · · International · Data Breaches

Navigate360, a platform that powers anonymous school safety tip lines, suffered a breach exposing 8.3 million tips in March 2026. Four months later, the company and the programs relying on its platform have provided little public disclosure, prompting DataBreaches.net to file complaints with state and federal regulators.

Why this matters: Anonymous tip lines exist on a single promise: that students who report threats or abuse will not be identified. That promise broke in March. Eight million tips means real names, real schools, real disclosures from kids who believed they were protected. Four months of silence from Navigate360 and the programs using its platform is not a communications failure. It is a betrayal of the people those programs were built to protect. When a company collects sensitive reports from minors and then goes quiet after a breach, regulators are the only lever left.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Breach
BleepingComputer · · International

Estée Lauder discloses data breach via Oracle E-Business flaw

Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

JadePuffer agentic attacks now target AI model data with ransomware

The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. [...]

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →
Breach
BleepingComputer · · International

New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
HIPAA Journal · · US Federal

23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit

23andMe, now operating as Chrome Holding Co., has agreed to an $18 million settlement with a coalition of 42 state attorneys general stemming from a data breach that exposed customer information. The multistate action represents one of the more significant coordinated enforcement responses to a consumer genetic data incident.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →