PrivacySignal
Breach

Marlboro-Chesterfield Pathology Agrees to Settle Lawsuit Over 2025 Ransomware Attack

HIPAA Journal · · US Federal · Data Breaches

Marlboro-Chesterfield Pathology, a molecular, cytology, and pathology lab based in Pinehurst, North Carolina, has agreed to settle a class action lawsuit stemming from a ransomware attack that occurred in 2025. The settlement resolves claims brought by patients whose data was potentially exposed in the breach.

Why this matters: Pathology labs hold some of the most sensitive medical data that exists — tissue samples, cancer diagnoses, genetic results, the kind of information people barely want to say out loud. When that data gets stolen, patients do not just face spam. They face potential exposure of conditions they may not have shared with anyone. A settlement means the lab avoids a full legal reckoning. It also means patients get something, but rarely enough to reflect what it actually costs to have your most private health details taken. The real accountability question is whether labs handling this kind of data are building security proportionate to the risk, or just hoping ransomware finds someone else first.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
CyberScoop · · US Federal

Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos

The two men face 14 charges combined. Private researchers traced one suspect through leaked passwords and a decade-old gaming profile. The post Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
The Record · · International

DOJ firearms agency says hackers breached system containing investigation targets

The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed it experienced a cyberattack on a system containing investigation information, as a prolific ransomware gang claimed to have carried out the breach.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement#security Read original →
Breach
BleepingComputer · · International

Carhartt data breach exposes information of 12.9 million accounts

The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

ATF confirms “major incident” after recent Qilin breach claims

ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang. [...]

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#regulation#security Read original →
Breach
CyberScoop · · US Federal

OpenAI: Agent behavior that led to Hugging Face intrusion formed in May

The company says the breach stemmed from a systemic failure of alignment and security, and has taken measures to prevent agents from independently orchestrating complex cyberattacks. The post OpenAI: Agent behavior that led to Hugging Face intrusion formed in May appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators