PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

504 results · page 17 of 21

Breach
BleepingComputer · · International

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

Estée Lauder discloses data breach via Oracle E-Business flaw

Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

Ostium, a crypto trading platform, lost nearly $23.75 million after an attacker compromised the off-chain system responsible for supplying price data to its protocol, draining funds from its liquidity provider vault. The breach did not target the blockchain directly but exploited the infrastructure connecting external data to the on-chain system.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
HIPAA Journal · · US Federal

23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit

23andMe, now operating as Chrome Holding Co., has reached an $18 million settlement with a coalition of 42 state attorneys general stemming from a data breach lawsuit. The agreement resolves multistate legal action against the genetic testing company.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Breach
The Record · · International

Hackers were inside South Korea's diplomat training system for 9 months

Unidentified hackers spent roughly nine months inside an online training system used by South Korea's diplomatic academy, extracting personal data belonging to current and former employees of the Ministry of Foreign Affairs. The breach was not detected for the duration of that access.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
HIPAA Journal · · US Federal

Centers Laboratory Discloses Data Breach Affecting 542K Individuals

Centers Lab NJ LLC, a New Jersey diagnostic testing laboratory, has disclosed a data breach affecting approximately 542,000 individuals. The breach involves personal and potentially medical information held by the healthcare services provider.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

Hugging Face warns an autonomous AI agent hacked its network

Hugging Face disclosed that attackers used an autonomous AI agent to breach its production infrastructure, gaining access to internal datasets and credentials. The AI model hosting platform is a central resource for researchers and developers across the machine learning community.

Who should care: Cybersecurity · Privacy officers · Administrators · AI governance · Lawyers · General readers · Policy

#breach#ai-governance#ai Read original →
Breach
DataBreaches.net · · International

Broken Promises of Anonymity: Four Months Later, Still No Transparency. Now We’re Seeking Accountability.

Navigate360, a platform that powers anonymous school safety tip lines, suffered a breach exposing 8.3 million tips in March 2026. Four months later, the company and the programs relying on its platform have provided little public disclosure, prompting DataBreaches.net to file complaints with state and federal regulators.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#regulation Read original →
Breach
WIRED — AI · · International

Your Period Tracker Is (Probably) Spying on You

A new report examines how period tracking apps collect and share sensitive reproductive health data, raising concerns about user exposure, particularly in jurisdictions where abortion access is legally restricted. The broader roundup also covers Russian cyber operations targeting infrastructure, repeated DHS security failures, and a breach revealing an AI music platform's data scraping practices.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
BleepingComputer · · International

Ernst & Young discloses data breach after support system hack

Ernst & Young has begun notifying customers of a data breach stemming from the compromise of a third-party support ticket system used by its IT staff. The breach originated outside EY's own infrastructure, in a vendor tool the firm relied on for internal technical support.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
HIPAA Journal · · US Federal

All About Women’s Care Data Breach Affects Up to 12,000 Patients

All About Women's Care, a Colorado-based healthcare provider, has notified approximately 12,000 patients that their personal information was exposed in a data breach. The incident was reported in the HIPAA Journal, which covers healthcare data security and compliance.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
DataBreaches.net · · International

The Breach That Won’t End: An Update on Canvas, and how they created an EdTech’s Vendor Trust Problem

Months after a breach at Instructure, the company behind the Canvas learning management system, affected educational institutions are still waiting for individualized findings. As of early July, Instructure had only begun delivering the first wave of institution-specific data packets, with the forensic review dragging well past initial timelines.

Who should care: Cybersecurity · Privacy officers · Administrators

Enforcement
DataBreaches.net · · International

Italy fines WINDTRE €1.7 million over data breaches

Italy's data protection authority fined telecom operator WINDTRE €1.7 million after finding serious security failures that led to two separate unauthorized breaches, exposing personal data belonging to more than 365,000 customers. The investigation was triggered by the company's own breach notification.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →
Breach
BleepingComputer · · International

23andMe to pay $18 million in new genetics data breach settlement

23andMe has agreed to an $18 million settlement with a coalition of 43 state attorneys general over its failure to adequately protect customers' genetic data from a breach. The settlement resolves multistate claims that the company did not take sufficient steps to secure some of the most sensitive personal information people can share.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
DataBreaches.net · · International

AU: Regulator’s preliminary findings did not indicate Qantas breached privacy obligations

Australia's privacy regulator conducted a preliminary inquiry into a 2025 Qantas data breach that exposed 5.67 million customer records and found no indication the airline likely violated the country's privacy obligations. The Office of the Australian Information Commissioner has not issued a final determination.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#regulation#privacy Read original →
Breach
HIPAA Journal · · US Federal

Vision Care Providers Settle Data Breach Class Actions

Two vision care providers, Total Vision in California and Naperville-area provider Naper Vision, have agreed to settlements resolving class action lawsuits stemming from data breaches. The cases were brought under health data privacy frameworks, with affected patients seeking compensation for the exposure of their personal and medical information.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Ohio Living; Erlanger; Heart of America Eye Care Announce Data Breaches

Three healthcare organizations — Ohio Living, a senior living provider, Erlanger Health System in Tennessee, and Heart of America Eye Care — have each disclosed separate data breaches. All three operate in sectors covered by HIPAA, meaning the compromised data likely includes sensitive medical and personal information.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Breach
DataBreaches.net · · International

Calgary 911 employee charged with breach of trust

A City of Calgary 911 employee has been charged with breach of trust after an investigation found she allegedly accessed and shared confidential information outside authorized channels. Calgary police say the investigation began in January following internal allegations about the unauthorized disclosure of sensitive data.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
DataBreaches.net · · International

WilmerHale Sued Over Client Personal Information Data Breach

A putative class action filed in federal court in Washington, D.C. accuses prominent law firm WilmerHale of negligence and breach of contract following a May data breach that allegedly exposed the personal information of thousands of clients. The plaintiffs are seeking millions of dollars in damages.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#enforcement#privacy Read original →
Breach
The Record · · International

23andMe reaches $18 million settlement with states for massive breach

A coalition of 42 state attorneys general has reached an $18 million settlement with genetic testing company 23andMe over cybersecurity failures that resulted in a large-scale data breach. The settlement resolves multistate legal action stemming from the company's failure to adequately protect user data.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
DataBreaches.net · · International

Files relating to India’s largest nuclear power plant Kudankulam exposed in data breach

Munsif Vengattil and Aditya Kalra Ransomware group World Leaks has posted on the dark web a huge cache of files related to India’s largest nuclear plant, including purported blueprints of parts of its ​facilities and supplier details — information it labelled as coming from Reliance Group. The Kudankulam Nuclear Power Plant, located in the southern... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

AU: Partnered Health Data Breach Exposes Patient Records at Family Clinics

Partnered Health, an Australian healthcare chain operating family medical clinics, has disclosed a cyberattack that exposed patient records across at least sixteen affected locations. The breach may include treatment information alongside personal data.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Community Health Center of Buffalo & Greenbaum Rowe Smith & Davis Confirm Data Breaches

Community Health Center of Buffalo and New Jersey law firm Greenbaum Rowe Smith & Davis have each disclosed separate data breaches. The incidents, reported via The HIPAA Journal, involve organizations that handle sensitive medical and legal information respectively.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Breach
HIPAA Journal · · US Federal

Physicians Primary Care of Southwest Florida Agrees to Data Breach Settlement

Physicians Primary Care of Southwest Florida has agreed to a settlement following a cyberattack in September 2024 that exposed patient data. The breach affected a primary care provider serving patients across Southwest Florida.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
← Prev Page 17 of 21 Next →