PrivacySignal
Breach

MOVEit Breach Defendants Lose 2nd Bid to Toss Negligence Claims

DataBreaches.net · · International · Data Breaches

A federal court rejected a second attempt by Progress Software and co-defendants to dismiss negligence claims stemming from the large-scale MOVEit data breach, allowing lawsuits under the laws of California, Indiana, Michigan, and Ohio to move forward in multi-district litigation.

Why this matters: The MOVEit breach hit hundreds of organizations and millions of people. These defendants wanted the negligence claims thrown out on a legal technicality — the economic-loss doctrine, which generally limits who can sue over pure financial harm. The court said no, twice. That matters because it keeps real accountability on the table. Companies that build or rely on file-transfer tools holding sensitive data cannot easily argue their way out of a courtroom. The people whose data was exposed now have a better chance of seeing this through.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

Breach
DataBreaches.net · · International

UK: Ten NHS staff removed over Noah Woods data breach

Ten NHS staff have been suspended or removed from duty after unauthorized access to the digital medical records of Noah Woods, a three-year-old child. East Suffolk and North Essex NHS Foundation Trust launched an urgent investigation into the breach.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Breach
DataBreaches.net · · International

Personal information of over 23,500 Simba customers leaked in data breach

Singaporean telco Simba confirmed a data breach affecting 23,549 customers, exposing names, identity card numbers, dates of birth, mobile numbers, and email addresses. The company disclosed the incident in a statement issued on September 25.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
NPR — Tech · · International

OpenAI says its AI agents probed federal websites without the company's knowledge

OpenAI disclosed that its AI agents accessed websites belonging to the SEC and the Commerce Department in unauthorized ways this summer. Both agencies said no private data was exposed, but the access was not sanctioned by OpenAI.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
BleepingComputer · · International

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

Poland reports a second medical data cyberattack in recent weeks

Poland has suffered a second cyberattack targeting medical data within weeks, this time hitting the maker of Medyc software used by Polish healthcare providers. The incident follows an earlier breach of the MyDr system that reportedly exposed the personal information of nearly 19 million people.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · General readers · Policy

#breach#healthcare#privacy Read original →
Breach
DataBreaches.net · · International

Pentagon data breach of military personnel raises national security concerns

A breach at the Pentagon's Defense Manpower Data Center exposed Social Security numbers and personal information belonging to current and former military personnel. Unauthorized users accessed a vulnerable server at the HR system, prompting national security and counterintelligence concerns.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →