PrivacySignal
Breach

Washington Dept. of Social and Health Services announces massive data breach

DataBreaches.net · · International · Data Breaches

Washington's Department of Social and Health Services disclosed that a former employee accessed personal data belonging to roughly 8,600 people without authorization in March. The agency launched an internal investigation and is now notifying those whose information may have been compromised.

Why this matters: The people affected here are not random customers. They are people who turned to a government social services agency — often at a low point, often with no choice. That means the data is likely sensitive: health conditions, financial situations, family circumstances. The threat was not an outside hacker. It was someone already inside, with access. That is a harder problem to solve. It also means the agency had a responsibility to monitor what employees were doing with this data, and it apparently took months to surface. People who had no option but to share their information with this agency deserved better controls than that.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
CyberScoop · · US Federal

Apollo discloses data breach from ongoing wave of attacks hitting financial sector

Apollo, a major private equity firm, disclosed that attackers accessed some of its cloud platforms over a five-day window in early July, exposing sensitive personal data. The breach is part of a broader wave of cyberattacks targeting financial sector firms.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
DataBreaches.net · · International

Troutman Pepper Locke Silent as Threat Actors Leak Client Data, Tens of Thousands of SSNs

In April, Silent Ransom Group’s (SRG)* leak site listed 38 law firms that had not paid them and whose data was leaked. By June 29, there were 48 law firms. Now there are 64, and, in somewhat surprising claims, SRG says a recent attack was actually its second on one law firm, and they will... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
The Record · · International

U.S. Bank says breach claims related to fourth-party incident

U.S. Bank has acknowledged claims of a data breach but says the incident originated with a fourth-party vendor, not its own systems. The bank states there is no evidence that its internal networks or data repositories were directly compromised.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

Hundreds of leaked AWS keys give full control over corporate accounts

More than 9,300 AWS access keys exposed publicly over a four-year period remain active and valid, giving anyone who finds them full control over the corporate cloud accounts they belong to. The keys were accessible between August 2022 and August 2026.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
HIPAA Journal · · US Federal

DAP Health Settles Data Breach Lawsuit for $1,300,000

DAP Health, a nonprofit community health network in Southern California, has agreed to a $1.3 million settlement to resolve a class action lawsuit stemming from a data breach. The case was reported by The HIPAA Journal, which covers healthcare privacy and compliance news.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →