PrivacySignal
Breach

Seoul Notifies 4.62 Million of Ttareungyi Data Breach, Offers Free Passes

DataBreaches.net · · International · Data Breaches

Seoul's municipal government is notifying approximately 4.62 million residents that their personal data was exposed in a breach of Ttareungyi, the city's public bike-sharing program. Affected users will receive text alerts detailing what was leaked, along with a 30-day free pass as compensation.

Why this matters: Over four million people signed up to borrow a bike. In return, they handed over personal details to a city-run service they had no reason to distrust. Now that data is out, and a free month of cycling is the city's answer. That is not nothing, but it does not fix the exposure. Public services collect membership data the same way private companies do, and they breach it the same way too. The question worth asking is what data Ttareungyi actually needed to run a bike-share, and whether holding it all in one place was ever justified.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
BleepingComputer · · International

IDScan sued over alleged data breach affecting 153 million drivers

Identity verification company IDScan faces multiple lawsuits after hackers allegedly broke into its systems and offered to sell data from more than 153 million driver's licenses on the open market.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
BleepingComputer · · International

39 New Methods That Compromise Passkey Authentication

Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

DaVita settles ransomware attack lawsuit for $15M

DaVita, a national kidney dialysis company, has agreed to a $15 million class action settlement following a 2025 ransomware attack that exposed patient data, much of which was subsequently leaked on the dark web.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare#security Read original →
Breach
DataBreaches.net · · International

FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans

A dark web service called Nexus began offering searchable access to more than 153 million scanned driver's licenses from the US and Canada, with IDScan.net suspected as the source of the breach. The FBI's New Orleans field office opened a formal investigation on the same day the service appeared.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →