PrivacySignal
Breach

UK’s state investments agency hit by data breach

The Guardian — Tech · · International · Data Breaches

UK Government Investments, the agency overseeing the state's stakes in public companies including Channel 4 and the Post Office, suffered a data breach that left sensitive management information and the personal details of more than 50 government officials publicly accessible for roughly 40 hours.

Why this matters: UKGI sits at the intersection of public money, government personnel, and sensitive corporate information. Forty hours is a long time for that kind of data to be sitting open. The officials exposed did not choose to hand their details to the public — their employer made that choice for them by failing to secure its systems. An agency trusted to protect taxpayer interests in major public companies needs to be able to protect its own data first. That is a basic expectation, and here it was not met.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Breach
DataBreaches.net · · International

A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach

They advertised and pinky swore “no logs.” But according to research by MysteriumVPN, they logged. Key takeaways from MysteriumVPN: A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database they claim was stolen from SplitVPN (formerly NotVPN), a Russian VPN used to bypass internet blocks. The Mysterium research team obtained... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

Brinks Home Confirms Data Breach Following ShinyHunters Claim

Guru Baran reports: Brinks Home, one of North America’s largest residential security providers, has confirmed that hackers breached its IT systems after the notorious ShinyHunters extortion group claimed responsibility for stealing nearly five million records tied to the company’s Salesforce environment. The confirmation comes after the threat actors listed “BH Security, LLC (brinkshome.com)” on their... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

TN: Sumner County Schools provides limited update on data breach

Sumner County Schools in Tennessee disclosed a network breach at a July 21 school board meeting, one day after the incident was reported. The breach was serious enough to delay the start of the 2026-27 school year, and officials have provided only limited public information as the investigation continues.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

Sixth Circuit to Rehear Case on FCC Data Breach Rules Case

The full Sixth Circuit will rehear a case that previously upheld the FCC's expanded data breach notification rules for telecommunications companies. The FCC, now under Republican leadership, has signaled it will likely roll back the rules regardless, but industry groups and Republican lawmakers are also pushing to eliminate the legal precedent the earlier ruling established.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#regulation Read original →
Breach
DataBreaches.net · · International

The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.

Spanish biopharmaceutical firm Diater has appeared on the dark web victim list published by the ransomware group DeadLock, which is using a double extortion strategy — encrypting data and threatening to publish it. The breach reportedly affects up to a decade of sensitive medical records belonging to patients and healthcare professionals.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
DataBreaches.net · · International

CareCloud Data Breach Impacts Over 350,000

Healthcare IT company CareCloud has begun notifying more than 350,000 people that their data was stolen after hackers accessed its AWS cloud environment in March 2025, disrupting an electronic health records system within its CareCloud Health division.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →