PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

408 results · page 17 of 17

Breach
D Digital Trends · · International

Hackers leak facial recognition records tied to millions of Madison Square Garden visitors

A hacker group has leaked a trove of facial recognition records linked to millions of people who visited Madison Square Garden, exposing biometric data collected by the venue's controversial surveillance system.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#surveillance#privacy Read original →
Breach
T TicketNews · · International

MSG Data Breach Lawsuit Puts Dolan’s Facial Recognition/Data Fight in Spotlight

A lawsuit stemming from a data breach at MSG Entertainment is drawing attention to the company's use of facial recognition technology and how it handles the personal data of people who attend its venues.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#enforcement#surveillance#privacy Read original →
Breach
EDPS · · EU

Managing Shadow AI’s Hidden Data Breach Risk

A blogpost by EDPS head Wojciech Wiewiórowski addresses the risks posed by unauthorized AI tools used inside organizations, noting that such tools can expose personal data, create regulatory blind spots, and introduce security vulnerabilities that official IT governance never sees.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · AI governance · Policy

#breach#regulation#ai#privacy#security Read original →
Breach
H HR Dive · · International

Cybersecurity, data privacy and AI may leave employers legally exposed

A growing convergence of cybersecurity risks, data privacy regulations, and AI adoption is creating significant legal liability for employers, according to analysis from HR Dive. Organizations face mounting exposure as workforce-related data practices come under intensified regulatory scrutiny.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#privacy Read original →
Breach
War on the Rocks · · International

The Gulf Arab States Need a Shield Built for Limited Trust

A new analysis argues that Gulf Cooperation Council defense institutions are too slow and permission-dependent to handle fast-moving missile, drone, and maritime threats. Recent crises in the Red Sea and Strait of Hormuz have exposed a gap between the region's cooperative security language and its ability to act in minutes rather than days.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
EFF — Deeplinks · · International

The 702 Ultimatum: Warrant Requirement or Bust

Congress faces a hard deadline on Section 702 of FISA, the surveillance authority that allows warrantless collection of communications involving foreign targets but routinely sweeps in Americans. Repeated short-term extensions have not produced agreement, and privacy advocates are now demanding a warrant requirement as the price of any renewal.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#surveillance#privacy Read original →
Breach
Krebs on Security · · International

Who Runs the Ransomware Group ‘The Gentlemen?’

A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
EDPB · · EU

EDPB meets with EU Commissioner McGrath and adopts common data breach notification template

The European Data Protection Board held its latest plenary session, meeting with EU Commissioner Michael McGrath to discuss shared priorities including the Digital Omnibus package, while also formally adopting a standardized template for data breach notifications across member states.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · AI governance · Compliance

#breach#gdpr#regulation Read original →
Breach
D Dentons · · International

Digital Omnibus on AI: Provisional compromise reshapes EU AI Act. Part 2: Data governance, innovation and extended deadlines for high-risk AI systems

EU negotiators have reached a provisional compromise under the Digital Omnibus package that modifies the AI Act, adjusting data governance requirements, reshaping innovation provisions, and extending compliance deadlines for operators of high-risk AI systems.

Who should care: Cybersecurity · Privacy officers · Administrators · AI governance · Lawyers · General readers · Policy

#breach#ai-governance#ai Read original →
Breach
EFF — Deeplinks · · International

VICTORY: Meta Strips Facial Recognition Code From Smart Glasses App After Public Outcry

After researchers and EFF's Threat Lab found hidden facial recognition code in Meta's smart glasses companion app — code capable of identifying strangers in public from a photo — Meta removed it following public backlash. The reversal came quietly, matching how the code was originally introduced.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#surveillance#ai#privacy Read original →
Breach
FTC Consumer Protection · · US Federal

FTC Gives Final Approval to Order Against Illuminate Settling Allegations It Failed to Secure Students’ Personal Data

The FTC has finalized a settlement with Illuminate Education over a data breach that exposed millions of students' personal information. The order mandates a formal security program, restrictions on how much student data the company may collect and retain, and deletion of data deemed unnecessary.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#enforcement#privacy Read original →
Breach
War on the Rocks · · International

The Pentagon’s AI Edge Is Being Distilled Away

A new analysis warns that adversaries may not need to hack U.S. military systems directly — they can study the publicly available commercial AI models that underpin Pentagon platforms and reverse-engineer their logic. As the Defense Department builds its warfighting capabilities on top of frontier AI from major tech companies, that commercial availability becomes a structural vulnerability.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
EDPB · · EU

The Italian SA fined Poste Vita for data breach

Italy's data protection authority issued an administrative fine against insurance firm Poste Vita S.p.A. following a customer complaint alleging unauthorized disclosure of personal data. The regulator found violations of GDPR principles governing data processing and breach-notification obligations.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#enforcement#privacy Read original →
Breach
IAPP · · International

Why data mining is functionally required after a HIPAA breach

Following a HIPAA breach, covered entities are effectively compelled to conduct extensive data mining to identify which records were exposed, assess the scope of harm, and meet regulatory notification obligations — making deep internal data analysis a practical necessity rather than an optional step.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
Krebs on Security · · International

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

A CISA contractor deliberately posted AWS GovCloud credentials and a large cache of agency secrets to a public GitHub repository, according to KrebsOnSecurity. Lawmakers in both chambers are now pressing CISA for answers while the agency works to revoke the exposed credentials.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
TechCrunch — Privacy · · International

Trump Mobile confirms it exposed customers’ personal data, including phone numbers and home addresses

Trump Mobile has acknowledged that a data exposure incident leaked customer personal information, including phone numbers and home addresses. The company attributed the breach to a third-party platform and said it is still assessing whether formal customer notification is required.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
TechCrunch — Privacy · · International

Customers say Trump Mobile is leaking their personal information

Trump Mobile customers report that their personal information, including email and home addresses, is being exposed in an apparent data leak. Two YouTubers say they independently confirmed the authenticity of their own leaked data, and the company has not responded to notifications about the problem.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
Krebs on Security · · International

CISA Admin Leaked AWS GovCloud Keys on Github

A contractor working for CISA left highly privileged AWS GovCloud credentials and internal system details exposed in a public GitHub repository until this past weekend. Security experts described the leaked archive, which included details about how the agency builds and deploys its own software, as one of the most serious government data exposures in recent memory.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
Information Commissioner's Office · · UK

Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach

The UK's Information Commissioner's Office has levied a fine of approximately £1 million against South Staffordshire Plc and its water utility subsidiary following a significant cyberattack that resulted in a personal data breach affecting customers.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
Dragos · · International

AI in the Breach: How an Adversary Leveraged AI to Target a Water Utility’s OT

Dragos has documented a case in which an adversary used AI tools to target the operational technology systems of a water utility. The incident marks a notable shift in how attackers are approaching critical infrastructure, using AI to probe or exploit systems that control physical processes.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
The Guardian — Privacy · · International

UK Biobank has my data, but I’m not worried. I know the benefits are too great to consider pulling out | Polly Toynbee

A dataset from UK Biobank — a large longitudinal health research repository — reportedly appeared for sale on Alibaba's platform in China, prompting concern among researchers and a warning from UK Science Minister Patrick Vallance that further such attempts are anticipated. Columnist Polly Toynbee argues the research value of such studies outweighs the risks.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
The Guardian — Privacy · · International

More private health records of UK Biobank volunteers appear on Chinese website

Additional confidential health records from UK Biobank's 500,000 volunteers have appeared for sale on Alibaba following last week's initial breach, with Science Minister Patrick Vallance confirming the government is coordinating with Chinese authorities to remove the listings and anticipating further exposures.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
The Guardian — Privacy · · International

Some Interrail travellers told to cancel passports as hacked data posted online

Eurail, the company behind Interrail passes, has disclosed that personal data from a December breach affecting around 300,000 travellers — including passport numbers, names, addresses, phone numbers, and dates of birth — has appeared for sale on the dark web. Some affected customers are now being advised to cancel and replace their passports.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
TechCrunch — Privacy · · International

Italian prosecutors confirm journalist was hacked with Paragon spyware

Italian prosecutors have confirmed that two journalists were targeted with Paragon spyware, advancing a broader national investigation into the tool's use. The identity of those who authorized or carried out the surveillance remains unknown.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement#surveillance Read original →
← Prev Page 17 of 17