PrivacySignal
Breach

Korea raises data breach fines to 10% of revenue

DataBreaches.net · · International · Data Breaches

South Korea's privacy regulator is raising the maximum fine for large-scale data breaches to 10% of a company's revenue, effective immediately. The change targets cases involving intent or gross negligence where at least 10 million people's personal data is exposed.

Why this matters: Fines set as a flat penalty are easy to treat as a line item. A percentage of revenue is harder to ignore, especially for large companies where a flat cap barely registers. Korea is making the math personal: the bigger you are, the more a breach costs you. That is a meaningful shift. It pushes companies to spend on protection before something goes wrong, not just pay up after. Other regulators will be watching to see if it actually changes behavior.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
HIPAA Journal · · US Federal

Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data

Veradigm, a Chicago-based electronic health records and practice management company formerly known as Allscripts Healthcare Solutions, has disclosed a cybersecurity incident involving a third-party breach. Hackers are threatening to publish the stolen data if their demands are not met.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

IDScan confirms breach tied to 153 million stolen driver’s licenses

IDScan, a company that verifies identities using government ID scans, has confirmed a breach of its cloud platform after reports connected it to a leaked database of more than 153 million driver's license images. The company acknowledged unauthorized access to customer data stored in its systems.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
HIPAA Journal · · US Federal

Palomar Health Medical Group; Summit Medical Group Settle Data Breach Lawsuits

Palomar Health Medical Group in California and Summit Medical Group have each agreed to settlements resolving class action lawsuits stemming from data breaches. The cases were reported by The HIPAA Journal, indicating the breaches involved protected health information.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach Critical
BleepingComputer · · International

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →