PrivacySignal
Breach

Japanese media group Nikkei discloses cyberattack targeting journalistic sources

The Record · · International · Data Breaches

Nikkei, the Japanese financial media group, disclosed a cyberattack that breached an employee email account and may have exposed the identities of journalistic sources.

Why this matters: Source confidentiality is not a technicality. It is the reason people talk to journalists at all. When a media company's email gets compromised, the damage is not just to the outlet. It can land on the people who trusted them with sensitive information, sometimes people who took real risks to speak up. Nikkei covers finance, business, and policy across Asia. The sources in those email threads may have had a lot to lose. A breach like this is a reminder that protecting sources requires treating their information with the same security discipline as any other high-value asset.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

Breach
DataBreaches.net · · International

Hackers Breached Propulsion System of U.S.-Bound Oil Tanker

FBI and U.S. Coast Guard investigators found evidence that hackers accessed the propulsion system of an oil supertanker as it was approaching the Texas coast this summer. The breach, confirmed by U.S. officials, represents a serious intrusion into a vessel's operational technology while it was actively navigating toward a major port.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

Ransomware group threatens to leak customer data from top insurance companies in South Africa

Luis Monzon reports: Ransomware-as-a-service group The Gentlemen threatened to leak data belonging to insurance companies LegalWise and Samwumed, with more South African companies likely to follow. The Gentlemen is one of the most active cybercriminal organisations in the world, and accounted for 17% of all ransomware attacks globally in July, according to Check Point Software.... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

Slate Valley Unified School District voted not to pay ransom demand; Kairos likely to leak data

The Slate Valley Unified School District in Fair Haven, Vermont, has been responding to a security incident since September 3. On October 2, Kairos threat actors contacted DataBreaches to alert us to the incident and their response to the district’s claim that they believed student data had not been compromised. They were also angry that... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

Italy’s Data Protection Authority fines IQVIA €7 million over data protection breach

Italy's data protection authority has fined IQVIA Solutions Italy €7 million after finding that health data belonging to roughly one million patients of 800 family doctors was not properly anonymized, in violation of data protection rules.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · AI governance · General readers · Policy

#breach#enforcement#gdpr#privacy Read original →
Breach
BleepingComputer · · International

Danish university DTU breach exposes data of up to 200,000 people

Hackers breached the Technical University of Denmark's identity and access management system, downloading data that may affect up to 200,000 people. DTU has disclosed the incident but details on what specific data was taken remain limited.

Who should care: Cybersecurity · Privacy officers · Administrators