PrivacySignal
Breach

Lawmakers propose giving 2015 OPM breach victims identity protection for life

Nextgov/FCW · · US Federal · Data Breaches

Legislators are proposing permanent identity protection services for the roughly 22 million people whose personal data was stolen in the 2015 Office of Personnel Management breaches, linked to Chinese state-backed hackers. Current federal coverage for those victims is set to expire on September 30.

Why this matters: The OPM breach was not a typical hack. The stolen records included security clearance applications, fingerprints, mental health history, financial data, and personal information on family members and references. That kind of data does not expire. Someone holding it can cause harm years or decades later. Cutting off protection on an arbitrary deadline treats a permanent exposure like a temporary inconvenience. These were federal employees and contractors who handed over sensitive details because the government required it. Covering them for life is the least it can do.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Breach
The Record · · International

Biotech giant Amgen says patient data stolen from third-party cloud systems

Amgen has disclosed to regulators that patient information and proprietary company data were accessed through a breach affecting third-party cloud systems the company relied on. The incident adds to a growing pattern of healthcare and biotech firms suffering data losses through vendors rather than their own internal infrastructure.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · Lawyers

#breach#healthcare#regulation Read original →
Breach
DataBreaches.net · · International

KR: Seoul lawmaker criticizes 5,000-won compensation for 4.62 million-person data breach

Seoul Facilities Corporation is facing political backlash over its proposed response to a data breach affecting approximately 4.62 million people. The company plans to offer each affected person roughly 5,000 won — about $3.50 USD — as compensation, a figure a Seoul city council member has publicly criticized as inadequate.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
DataBreaches.net · · International

UK: Details of 100,000 police staff leaked on the dark web after hack

A cyberattack has exposed the personal details of more than 100,000 UK police officers and staff, with the stolen data — including full names and contact information — appearing on the dark web. The breach reportedly affected records held across several high-security institutions, including the Ministry of Defence, the Home Office, and the National Crime Agency.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach

They advertised and pinky swore “no logs.” But according to research by MysteriumVPN, they logged. Key takeaways from MysteriumVPN: A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database they claim was stolen from SplitVPN (formerly NotVPN), a Russian VPN used to bypass internet blocks. The Mysterium research team obtained... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

Brinks Home Confirms Data Breach Following ShinyHunters Claim

Guru Baran reports: Brinks Home, one of North America’s largest residential security providers, has confirmed that hackers breached its IT systems after the notorious ShinyHunters extortion group claimed responsibility for stealing nearly five million records tied to the company’s Salesforce environment. The confirmation comes after the threat actors listed “BH Security, LLC (brinkshome.com)” on their... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →