PrivacySignal
Breach

Data breach incident targets prisoner medical records at 2 Mass. jails

DataBreaches.net · · International · Data Breaches

A cybersecurity incident has compromised the electronic health record system used at two Suffolk County jails in Massachusetts. The system provider, Computer Systems Integrated Inc., confirmed it is investigating the breach, which exposed prisoner medical and health data stored on its EHRs-C platform.

Why this matters: People in jail still have medical privacy rights. Their records can contain mental health history, addiction treatment, medications, and chronic conditions — sensitive details that can follow someone long after release. Incarcerated people cannot switch providers or opt out of the systems holding their data. That makes a breach here worse, not better. The vendor runs the platform; the county chose the vendor. Both need to answer for what was exposed and who might have it now.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

Breach
BleepingComputer · · International

Former US Air Force members sent to prison over BEC attacks

Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
Microsoft Threat Intelligence · · International

​​Beyond source code: A path to the keys to the kingdom

Explore how Storm-3068 turned a compromised identity into broader cloud access and the steps organizations can take to defend their identities, pipelines, and cloud infrastructure. The post ​​Beyond source code: A path to the keys to the kingdom appeared first on Microsoft Security Blog.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

Automated AI agent used to breach cybersecurity nonprofit DIVD

The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →
Breach
CyberScoop · · US Federal

Alleged ShinyHunters leader arrested in the Netherlands

Dutch authorities arrested a 24-year-old Amsterdam man alleged to be a leader of the ShinyHunters hacking group. The arrest came roughly one week before the group carried out a separate hack against the FBI.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
Microsoft Threat Intelligence · · International

Star Blizzard refines phishing and malware delivery with the RedFlick technique

Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”. The post Star Blizzard refines phishing and malware delivery with the RedFlick technique appeared first on Microsoft Security Blog.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →