PrivacySignal
Breach

DaVita settles ransomware attack lawsuit for $15M

DataBreaches.net · · International · Data Breaches

DaVita, a national kidney dialysis company, has agreed to a $15 million class action settlement following a 2025 ransomware attack that exposed patient data, much of which was subsequently leaked on the dark web.

Why this matters: Dialysis patients cannot shop around. They depend on DaVita, and in doing so they hand over some of the most sensitive health data that exists. When that data ends up on the dark web, a $15 million settlement does not undo the exposure. It mostly signals what a company was willing to pay to close the case. The people whose records were leaked live with that risk indefinitely. Healthcare providers hold data that can affect insurance, employment, and personal safety — the security around it needs to reflect that.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
BleepingComputer · · International

39 New Methods That Compromise Passkey Authentication

Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans

A dark web service called Nexus began offering searchable access to more than 153 million scanned driver's licenses from the US and Canada, with IDScan.net suspected as the source of the breach. The FBI's New Orleans field office opened a formal investigation on the same day the service appeared.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
DataBreaches.net · · International

TR: Fine for famous kebab chain that allowed theft of 500 thousand customers’ data

Turkey's data protection authority fined restaurant chain Baydöner after a breach exposed the personal data of over 500,000 customers, including names, phone numbers, email addresses, and location information. The investigation found the company had no system in place to detect unusual activity before the theft occurred.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · AI governance · General readers · Policy

#breach#enforcement#gdpr#privacy Read original →
Breach
HIPAA Journal · · US Federal

Midwest Spine and Brain Institute Impacted by Vendor Ransomware Attack

Midwest Spine and Brain Institute, along with Brookhaven ENT Allergy and Facial Surgery and Digestive Disease Center, have disclosed data breaches stemming from a ransomware attack on a shared vendor. The incidents follow a pattern of healthcare providers being exposed through third-party service relationships.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
C Congressman Mike Lawler (.gov) · · International

Exclusive: New bill cracks down on AI agents after Hugging Face breach

A new congressional bill targeting AI agents is in the works, reportedly prompted in part by a security breach at Hugging Face. The legislation appears aimed at tightening oversight or regulation of autonomous AI systems.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →