PrivacySignal
Breach

The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.

DataBreaches.net · · International · Data Breaches

Spanish biopharmaceutical firm Diater has appeared on the dark web victim list published by the ransomware group DeadLock, which is using a double extortion strategy — encrypting data and threatening to publish it. The breach reportedly affects up to a decade of sensitive medical records belonging to patients and healthcare professionals.

Why this matters: Medical records are not recoverable the way a password is. If DeadLock publishes what it took from Diater, patients cannot change their diagnoses, test results, or treatment histories. Ten years of data means the exposure is deep. Double extortion makes it worse: the company is under pressure to pay, and the people whose data is at stake have no say in that negotiation and no way to protect themselves. This is the core problem with how healthcare organizations hold sensitive data — the patients bear the risk, but the company makes the call.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
DataBreaches.net · · International

Payroll system of mosques, madrasahs hit by ransomware; staff details potentially compromised

David Sun reports: The payroll system of mosques and madrasahs overseen by the Islamic Religious Council of Singapore (MUIS) has been hacked and held for ransom, The Straits Times has learnt. The SmartHRMS human resources (HR) system is supplied by Singapore-based software vendor Avelogic. The latest cybersecurity incident notice on Avelogic’s website, which was last... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
The Guardian — Tech · · International

Labor accused of throwing creatives ‘under the bus’ with proposal to ease copyright protections for AI giants

Compromise revealed as senior personnel from OpenAI, creator of ChatGPT, meets Albanese ministers Follow our Australia news live blog for latest updates Get our new political email, free app or daily news podcast The Albanese government is considering giving AI companies access to Australian creatives’ works by default as it pursues a compromise with US tech giants. The proposals were revealed as senior personnel from OpenAI, the creator of ChatGPT, met with Labor ministers and warned that Australia’s copyright laws were preventing the company from training models locally. Sign up for Guardia…

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
BleepingComputer · · International

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

CenterPoint Energy confirms customer data stolen in cyberattack

CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →