PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

408 results · page 12 of 17

Breach
Privacy Commissioner of Canada · · Canada

News release: WestJet commits to improving security measures following a data breach

I need to work with what the headline and label imply — a WestJet news release announcing commitments to improve security following a data breach — without inventing specifics. ```json { "summary": "WestJet has issued a public statement committing to strengthen its security practices in the wake

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
Military Times · · US Federal

Nearly 12,000 military Tricare beneficiaries warned of data breach

TriWest Healthcare Alliance has notified nearly 12,000 military Tricare beneficiaries that their protected health information may have been exposed in a data breach. The notification indicates the incident was significant enough to trigger formal disclosure requirements under federal health privacy rules.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
Microsoft Threat Intelligence · · International

Defending SaaS-based applications against ShinyHunters OAuth abuse

Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-based applications. The post Defending SaaS-based applications against ShinyHunters OAuth abuse appeared first on Microsoft Security Blog.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

Japan's largest taxi operator shuts systems after cyberattack

Nihon Kotsu, Japan's largest taxi operator, suffered a cyberattack that forced the company to take portions of its systems offline. The company has not disclosed the scope of the breach or what data may have been affected.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
The Record · · International

VPN service favored by ransomware groups is sanctioned by US

The U.S. Treasury Department announced sanctions against First VPN Service (1VPNS) and its Ukrainian administrator for aiding ransomware groups. Separately, a Belarusian man was sanctioned for malware "cryptors."

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

NG: Zenith Bank, Others To Be Arraigned Over Alleged Data Breach

A Nigerian Federal High Court has scheduled the arraignment of Zenith Bank and three individual defendants for July 21, 2026, on allegations that they illegally accessed and disclosed confidential financial records belonging to Makers Island Company Limited.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
The Record · · International

Russian celebrity journalist Ksenia Sobchak says hackers accessed Telegram channels via email breach

Russian journalist Ksenia Sobchak says hackers gained access to her Telegram channels through an email breach, after screenshots of her private correspondence with political figures were published online. Sobchak has denied the authenticity of the leaked messages, calling them fabricated.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
Military Times · · US Federal

US creates task force to prosecute leaks to news media, Hegseth says

The Justice Department and Pentagon have established a joint task force focused on identifying and prosecuting government leaks to news organizations, according to Defense Secretary Pete Hegseth. The move marks a formal, coordinated escalation of the federal government's effort to pursue unauthorized disclosures to journalists.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
Nextgov/FCW · · US Federal

DHS network intrusion was twice ruled a false positive before breach confirmed

Suspicious network activity on a Department of Homeland Security system supporting U.S. World Cup operations was initially flagged twice as a false positive before investigators confirmed an actual intrusion had occurred. The breach involved the Homeland Security Information Network, a platform used to coordinate security efforts around the event.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
Krebs on Security · · International

Lessons Learned from CISA’s Recent GitHub Leak

CISA released a postmortem after a contractor accidentally published dozens of internal credentials, including AWS GovCloud keys, to a public GitHub repository, where they sat exposed for nearly six months before journalist Brian Krebs alerted the agency. Security experts say the incident reveals gaps in how CISA detected and responded to the exposure.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

Lidl discloses online shop breach after service provider hack

Lidl has notified customers in Germany, Belgium, and the Netherlands that their personal data was stolen through a breach at a third-party service provider. The discount supermarket chain disclosed the incident after attackers compromised the external vendor rather than Lidl's own systems.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
BleepingComputer · · International

Breach at the Beach: Play the Ultimate Entra ID CTF

Varonis has released a free, hands-on Capture the Flag challenge designed to teach security practitioners how attackers exploit Microsoft Entra ID, using realistic scenarios to simulate common identity-based attack techniques.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
HIPAA Journal · · US Federal

Marlboro-Chesterfield Pathology Agrees to Settle Lawsuit Over 2025 Ransomware Attack

Marlboro-Chesterfield Pathology, a molecular, cytology, and pathology lab based in Pinehurst, North Carolina, has agreed to settle a class action lawsuit stemming from a ransomware attack that occurred in 2025. The settlement resolves claims brought by patients whose data was potentially exposed in the breach.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare#security Read original →
Breach
HIPAA Journal · · US Federal

California Gay & Lesbian Services Center Data Breach Affects 75,500 Individuals

The Gay & Lesbian Community Services Center of Orange County, California, has disclosed a data breach affecting approximately 75,500 individuals. The organization provides mental health services, HIV testing, education, and outreach to its community.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
DataBreaches.net · · International

Armenian National Extradited to the United States Pleads Guilty to Ransomware Extortion Conspiracy

PORTLAND, Ore.— An Armenian national extradited from Ukraine to the United States pleaded guilty yesterday for his role in Ryuk ransomware attacks and an extortion conspiracy targeting companies throughout the United States, including a technology company operating in Oregon. Karen Serobovich Vardanyan, 34, pleaded guilty to conspiracy and computer fraud. According to court documents, between... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

Ransomware negotiator who conspired with BlackCat threat actors sentenced to 70 months in prison

Jon Brodkin reports that a third co-conspirator who helped BlackCat attackers by giving them inside information on victims’ defense strategies has now been sentenced. A former ransomware negotiator was sentenced to 70 months in prison yesterday after colluding with BlackCat scammers to extort the victims he was hired to protect. As a ransomware negotiator for the company DigitalMint,... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

TikTok class action alleges data breach affected 2.4B users

A California resident filed a federal class action lawsuit against TikTok on June 11, 2026, alleging a data breach exposed the personal information of more than 2.4 billion users. The complaint claims TikTok stored user data without encryption and failed to implement basic security measures.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#enforcement#privacy Read original →
Breach
DataBreaches.net · · International

Dutch police trace Odido telco cyberattack to suspected local accomplice; May leak voice recording

Dutch police investigating a cyberattack on telecom provider Odido, which exposed personal data of over 6 million customers, have identified a suspected local accomplice. Authorities say a Dutch-speaking man impersonated an Odido IT employee in what appears to have been a social engineering step linked to the breach.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
BleepingComputer · · International

New U-Boot flaws could enable stealthy firmware attacks

Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
Schneier on Security · · International

Friday Squid Blogging: “Squidbleed” Vulnerability

In a rare combined cybersecurity/squid post, a twenty-nine-year-old squid proxy bug can leak HTTP requests. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
CyberScoop · · US Federal

Armenian national pleads guilty to Ryuk ransomware attacks

Karen Vardanyan faces up to 15 years in federal prison and agreed to pay nearly $1.2 million in restitution. The post Armenian national pleads guilty to Ryuk ransomware attacks appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
CyberScoop · · US Federal

CISA looks to remedy ailments from big May credential leak

A major credential leak spurred the Cybersecurity and Infrastructure Security Agency to strengthen protections for its sensitive materials, improve how researchers can report agency vulnerabilities and develop plans for similar incidents, the agency said in a forensic report released Thursday. The blog post outlines CISA’s response to the leak that the researcher who discovered it […] The post CISA looks to remedy ailments from big May credential leak appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
← Prev Page 12 of 17 Next →