PrivacySignal
Breach

T-Mobile violated WA data breach notification law, judge rules

DataBreaches.net · · International · Data Breaches

A King County Superior Court judge ruled that T-Mobile violated Washington State's data breach notification law after a breach exposed sensitive personal information belonging to 40 million people, with the stolen data later sold on the dark web. The case was brought by Washington's attorney general in January 2025.

Why this matters: Forty million people had their data stolen and sold, and T-Mobile did not tell them the way the law requires. That is the core of it. Notification laws exist for a simple reason: people deserve a chance to protect themselves after a breach. If you do not hear about it quickly, you cannot freeze your credit, change passwords, or watch for fraud. A judge deciding a major carrier broke that rule is accountability worth paying attention to. The penalty phase will say a lot about whether these laws have real teeth.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Breach
BleepingComputer · · International

Chick-fil-A data breach affects more than 13,000 customers

Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

Crime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked.

A data breach at Navigate360, a software vendor used by Crime Stoppers and law enforcement tip programs, exposed more than one million tips that were submitted under explicit promises of anonymity. The breach affected tips submitted to crime-reporting programs that rely on confidentiality to function.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
DataBreaches.net · · International

Origin silent on settlement as alleged fired employee breach detail emerges

Origin Energy has not confirmed or denied reports that it quietly settled a cyber extortion demand, while details have emerged suggesting the alleged breach point was a terminated former employee's credentials. The company faces overlapping disclosure obligations to regulators, the Australian Securities Exchange, and insurers as the situation develops.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement#regulation Read original →
Breach
DataBreaches.net · · International

Clop gang targets Windchill, FlexPLM in data theft attacks

Sergiu Gatlan reports: The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. As cybersecurity company... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
HIPAA Journal · · US Federal

Tennessee Pathology Group Announces 170K-record Data Breach

Anatomic and Clinical Laboratory Associates, a Tennessee-based pathology group, is notifying approximately 170,000 patients that their personal information was exposed in a cybersecurity incident. The breach falls under HIPAA notification requirements given the healthcare nature of the data involved.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →