PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

407 results · page 10 of 17

Breach
The Record · · International

Kenya probes hack of president's website after bitcoin ransom demand

Kenya's government is investigating a hack of President William Ruto's official website after attackers replaced the homepage with a ransom message over the weekend, demanding bitcoin payment and threatening to release unspecified information about the president if the demand was not met.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
The Guardian — Tech · · International

How AI may drive union-resistant tech workers to the bargaining table

Tech workers, long resistant to unionization due to high pay and flat hierarchies, are increasingly turning to collective bargaining as AI reshapes their jobs. The shift reflects growing concern that companies are deploying AI in ways that workers have little power to contest on their own.

Who should care: Cybersecurity · Privacy officers · Administrators · AI governance · Lawyers · General readers · Policy

#breach#ai-governance#ai Read original →
Breach
HIPAA Journal · · US Federal

ApolloMD Agrees to Pay $4.02M to Settle Data Breach Lawsuit

ApolloMD Business Services, a healthcare staffing and practice management company, has agreed to pay $4.02 million to settle a lawsuit stemming from a data breach. As a business associate under HIPAA, ApolloMD handles patient data on behalf of healthcare providers.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Breach
BleepingComputer · · International

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

Estée Lauder discloses data breach via Oracle E-Business flaw

Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

Ostium, a crypto trading platform, lost nearly $23.75 million after an attacker compromised the off-chain system responsible for supplying price data to its protocol, draining funds from its liquidity provider vault. The breach did not target the blockchain directly but exploited the infrastructure connecting external data to the on-chain system.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

JadePuffer agentic attacks now target AI model data with ransomware

The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. [...]

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →
Breach
The Record · · International

India says allegedly leaked nuclear plant files pose no safety risk

Indian officials responded to claims by the cybercrime group World Leaks that it had leaked files from the Kudankulam Nuclear Power Plant, stating that the documents do not contain safety or security-relevant information. The government has not denied that a leak occurred, only that the content is not sensitive.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
HIPAA Journal · · US Federal

23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit

23andMe, now operating as Chrome Holding Co., has reached an $18 million settlement with a coalition of 42 state attorneys general stemming from a data breach lawsuit. The agreement resolves multistate legal action against the genetic testing company.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Breach
The Record · · International

Hackers were inside South Korea's diplomat training system for 9 months

Unidentified hackers spent roughly nine months inside an online training system used by South Korea's diplomatic academy, extracting personal data belonging to current and former employees of the Ministry of Foreign Affairs. The breach was not detected for the duration of that access.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
HIPAA Journal · · US Federal

Centers Laboratory Discloses Data Breach Affecting 542K Individuals

Centers Lab NJ LLC, a New Jersey diagnostic testing laboratory, has disclosed a data breach affecting approximately 542,000 individuals. The breach involves personal and potentially medical information held by the healthcare services provider.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

Hugging Face warns an autonomous AI agent hacked its network

Hugging Face disclosed that attackers used an autonomous AI agent to breach its production infrastructure, gaining access to internal datasets and credentials. The AI model hosting platform is a central resource for researchers and developers across the machine learning community.

Who should care: Cybersecurity · Privacy officers · Administrators · AI governance · Lawyers · General readers · Policy

#breach#ai-governance#ai Read original →
Breach
DataBreaches.net · · International

Broken Promises of Anonymity: Four Months Later, Still No Transparency. Now We’re Seeking Accountability.

Navigate360, a platform that powers anonymous school safety tip lines, suffered a breach exposing 8.3 million tips in March 2026. Four months later, the company and the programs relying on its platform have provided little public disclosure, prompting DataBreaches.net to file complaints with state and federal regulators.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#regulation Read original →
Breach
WIRED — AI · · International

Your Period Tracker Is (Probably) Spying on You

A new report examines how period tracking apps collect and share sensitive reproductive health data, raising concerns about user exposure, particularly in jurisdictions where abortion access is legally restricted. The broader roundup also covers Russian cyber operations targeting infrastructure, repeated DHS security failures, and a breach revealing an AI music platform's data scraping practices.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
The Guardian — Tech · · International

Trump has normalized crypto. Is it the path to the next financial collapse? | Eduardo Porter

A commentary piece argues that President Trump's personal financial stake in cryptocurrency — reportedly over a billion dollars earned last year — creates a direct conflict of interest as his administration moves to mainstream digital assets, potentially setting the stage for broader economic instability.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
Volexity · · International

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

Security firm Volexity discovered in early July 2026 that threat actors had exploited a zero-day vulnerability in SonicWall Secure Mobile Access VPN appliances, compromising the devices during an active incident response investigation. The attack targeted the remote access hardware that organizations rely on to connect employees securely to corporate networks.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement#security Read original →
Breach
BleepingComputer · · International

Ernst & Young discloses data breach after support system hack

Ernst & Young has begun notifying customers of a data breach stemming from the compromise of a third-party support ticket system used by its IT staff. The breach originated outside EY's own infrastructure, in a vendor tool the firm relied on for internal technical support.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
HIPAA Journal · · US Federal

All About Women’s Care Data Breach Affects Up to 12,000 Patients

All About Women's Care, a Colorado-based healthcare provider, has notified approximately 12,000 patients that their personal information was exposed in a data breach. The incident was reported in the HIPAA Journal, which covers healthcare data security and compliance.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

Coca-Cola says Fairlife ransomware attack halts US dairy production

The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

The Breach That Won’t End: An Update on Canvas, and how they created an EdTech’s Vendor Trust Problem

Months after a breach at Instructure, the company behind the Canvas learning management system, affected educational institutions are still waiting for individualized findings. As of early July, Instructure had only begun delivering the first wave of institution-specific data packets, with the forensic review dragging well past initial timelines.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

23andMe to pay $18 million in new genetics data breach settlement

23andMe has agreed to an $18 million settlement with a coalition of 43 state attorneys general over its failure to adequately protect customers' genetic data from a breach. The settlement resolves multistate claims that the company did not take sufficient steps to secure some of the most sensitive personal information people can share.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
The Guardian — Tech · · International

TikTok facing UK investigation amid fears over age checks and harm to children

UK media regulator Ofcom has opened a formal investigation into TikTok over concerns that its age verification measures are ineffective, potentially leaving children exposed to content about suicide, self-harm, and pornography. The probe comes roughly a year after child protection requirements under the Online Safety Act took effect.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement#regulation Read original →
Breach
DataBreaches.net · · International

AU: Regulator’s preliminary findings did not indicate Qantas breached privacy obligations

Australia's privacy regulator conducted a preliminary inquiry into a 2025 Qantas data breach that exposed 5.67 million customer records and found no indication the airline likely violated the country's privacy obligations. The Office of the Australian Information Commissioner has not issued a final determination.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#regulation#privacy Read original →
← Prev Page 10 of 17 Next →