PrivacySignal
Breach

No Need to Hack When It’s Leaking: Click to Pray edition

DataBreaches.net · · International · Data Breaches

Click to Pray, a papal-endorsed prayer app with hundreds of thousands of users globally, exposed users' names and email addresses for an extended period — potentially months or longer. An ethical hacker discovered and reported the leak.

Why this matters: People downloading a faith app are not thinking about their data footprint. They are trying to pray. That trust makes the exposure worse. Names and emails tied to a religious app can reveal something personal — belief, practice, community — that users never meant to share with anyone. No sophisticated attack was needed here. The data was just sitting out. That is not bad luck. That is a failure to do the basics, and the people who got hurt had no way to know it was happening.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
BleepingComputer · · International

ShinyHunters hackers claim breach of Florida "DAVID" DMV database

The ShinyHunters hacking group claims to have breached DAVID, an online platform connected to the Florida DMV, and obtained more than 200,000 driver records. The group has a history of large-scale data theft and extortion.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
HIPAA Journal · · US Federal

OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement

OneTouchPoint, a Wisconsin-based mailing and printing vendor, has agreed to a multi-million dollar class action settlement stemming from a 2022 ransomware attack. The case, reported by The HIPAA Journal, suggests the breach involved health-related data handled on behalf of the company's clients.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare#security Read original →
Breach
HIPAA Journal · · US Federal

NFI North Data Breach Affects Almost 50,000 Individuals

NFI North, a New Hampshire-based organization, disclosed a data breach affecting nearly 50,000 individuals. The breach was reported alongside separate incidents at Nephrology Associates in Kansas and PAMCAH-UA Local 675 Health, suggesting a broader pattern of healthcare and benefits-sector breaches.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
C cio.com · · International

The EU AI Act just gave you a breach notification clock you didn’t know about

The EU AI Act contains breach notification requirements that many organizations may not have recognized as such, creating compliance deadlines that could catch unprepared companies off guard.

Who should care: Cybersecurity · Privacy officers · Administrators · AI governance · Lawyers · General readers · Policy

#breach#ai-governance#ai Read original →
Breach
New York Times — Tech · · International

A.I. Models Built a Computer Worm That Could Rapidly Hack WeChat Accounts

AI researchers built a computer worm using AI models that was capable of rapidly compromising WeChat accounts at massive scale. Experts said the attack could have affected hundreds of millions of devices within hours if deployed.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

220 million traveler records exposed in Vietnam-linked APIS leak

A misconfigured Advance Passenger Information System database linked to Vietnam exposed roughly 220 million passenger and crew records, including passport numbers, dates of birth, nationalities, and flight details covering nearly a decade. Researchers reached the cloud-hosted system using default credentials, suggesting basic security controls were never changed.

Who should care: Cybersecurity · Privacy officers · Administrators