PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

504 results · page 21 of 21

Breach
IAPP · · International

Notes from the Asia-Pacific region: Breach could spark shift in New Zealand privacy law

A data breach in New Zealand is prompting discussion about potential reforms to the country's privacy legislation, according to reporting from the IAPP. The incident may accelerate legislative changes to how personal data is protected under New Zealand law.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
DataBreaches.net · · International

No need to hack when it’s leaking: Dialog edition

A data exposure at Dialog, described as an exclusive, invite-only organization, left membership information accessible without any breach in the conventional sense. The organization reportedly framed the incident as a hack, though the data appears to have been leaking rather than stolen through an intrusion.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
HIPAA Journal · · US Federal

Bradford Health Services; Bradford Health Partners Settle Data Breach Lawsuit

Bradford Health Services and Bradford Health Partners have agreed to settle a lawsuit stemming from a December 2023 cybersecurity incident that exposed patient data. The breach prompted legal action under privacy and healthcare data protection laws.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Breach
HIPAA Journal · · US Federal

Hillcrest Convalescent Center Settles Class Action Data Breach Litigation

Hillcrest Convalescent Center, a skilled nursing and rehabilitation facility in Durham, North Carolina, has reached a settlement in a class action lawsuit stemming from a data breach affecting patient information.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

British Scattered Spider Hacker Pleads Guilty to Cyberattacks on TfL; SSM Health Care; Sutter Health

A British member of the Scattered Spider hacking group has pleaded guilty to cyberattacks on Transport for London, SSM Health Care, and Sutter Health, with a second British hacker also pleading guilty in connection with the TfL breach. The cases mark a rare instance of criminal accountability for a group linked to a string of high-profile intrusions.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Breach
R Reuters · · International

India's Tata Electronics hit by cyber breach claiming to expose Apple, Tesla trade secrets

Tata Electronics, a major supplier to companies including Apple and Tesla, has reportedly suffered a cyberattack in which threat actors claim to have obtained sensitive trade secrets tied to those client relationships. The full scope of the breach and the validity of the claims have not been independently confirmed.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
T TicketNews · · International

MSG Data Breach Lawsuit Puts Dolan’s Facial Recognition/Data Fight in Spotlight

A lawsuit stemming from a data breach at MSG Entertainment is drawing attention to the company's use of facial recognition technology and how it handles the personal data of people who attend its venues.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#enforcement#surveillance#privacy Read original →
Breach
EDPS · · EU

Managing Shadow AI’s Hidden Data Breach Risk

A blogpost by EDPS head Wojciech Wiewiórowski addresses the risks posed by unauthorized AI tools used inside organizations, noting that such tools can expose personal data, create regulatory blind spots, and introduce security vulnerabilities that official IT governance never sees.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · AI governance · Policy

#breach#regulation#ai#privacy#security Read original →
Breach
EDPB · · EU

EDPB meets with EU Commissioner McGrath and adopts common data breach notification template

The European Data Protection Board held its latest plenary session, meeting with EU Commissioner Michael McGrath to discuss shared priorities including the Digital Omnibus package, while also formally adopting a standardized template for data breach notifications across member states.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · AI governance · Compliance

#breach#gdpr#regulation Read original →
Breach
FTC Consumer Protection · · US Federal

FTC Gives Final Approval to Order Against Illuminate Settling Allegations It Failed to Secure Students’ Personal Data

The FTC has finalized a settlement with Illuminate Education over a data breach that exposed millions of students' personal information. The order mandates a formal security program, restrictions on how much student data the company may collect and retain, and deletion of data deemed unnecessary.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#enforcement#privacy Read original →
Breach
War on the Rocks · · International

The Pentagon’s AI Edge Is Being Distilled Away

A new analysis warns that adversaries may not need to hack U.S. military systems directly — they can study the publicly available commercial AI models that underpin Pentagon platforms and reverse-engineer their logic. As the Defense Department builds its warfighting capabilities on top of frontier AI from major tech companies, that commercial availability becomes a structural vulnerability.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
EDPB · · EU

The Italian SA fined Poste Vita for data breach

Italy's data protection authority issued an administrative fine against insurance firm Poste Vita S.p.A. following a customer complaint alleging unauthorized disclosure of personal data. The regulator found violations of GDPR principles governing data processing and breach-notification obligations.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#enforcement#privacy Read original →
Enforcement
EDPB · · EU

The Italian SA imposed a 40 000 EUR fine on a company for violating the confidentiality of a employee's email account after the end of his employment

Italy's data protection authority fined LTL S.p.A. €40,000 for accessing a former employee's work email account after his employment ended, breaching GDPR principles on lawful processing, transparency, and the individual's right to access his own data.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#regulation#privacy Read original →
Breach
IAPP · · International

Why data mining is functionally required after a HIPAA breach

Following a HIPAA breach, covered entities are effectively compelled to conduct extensive data mining to identify which records were exposed, assess the scope of harm, and meet regulatory notification obligations — making deep internal data analysis a practical necessity rather than an optional step.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
Krebs on Security · · International

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

A CISA contractor deliberately posted AWS GovCloud credentials and a large cache of agency secrets to a public GitHub repository, according to KrebsOnSecurity. Lawmakers in both chambers are now pressing CISA for answers while the agency works to revoke the exposed credentials.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
TechCrunch — Privacy · · International

Trump Mobile confirms it exposed customers’ personal data, including phone numbers and home addresses

Trump Mobile has acknowledged that a data exposure incident leaked customer personal information, including phone numbers and home addresses. The company attributed the breach to a third-party platform and said it is still assessing whether formal customer notification is required.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
News
IAPP · · International

Notes from the IAPP Canada: Special report on CRA breaches raises fresh privacy concerns

A special report discussed at IAPP Canada has renewed scrutiny over privacy breaches at the Canada Revenue Agency, drawing attention to how sensitive taxpayer data has been compromised. The report surfaces ongoing concerns about the CRA's ability to protect the personal and financial information it holds on virtually every Canadian adult.

Who should care: General readers · Privacy officers · Policy

Breach
Information Commissioner's Office · · UK

Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach

The UK's Information Commissioner's Office has levied a fine of approximately £1 million against South Staffordshire Plc and its water utility subsidiary following a significant cyberattack that resulted in a personal data breach affecting customers.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Enforcement
Privacy Commissioner of Canada · · Canada

News release: Privacy Commissioner of Canada investigation into breaches leads to Canada Revenue Agency commitment to improve security measures

I need to work from what the headline implies: Canada's Privacy Commissioner investigated data breaches at the Canada Revenue Agency, and the CRA has committed to improving its security practices as a result. ```json { "summary": "Canada's Privacy Commissioner completed an investigation into data

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Breach
Dragos · · International

AI in the Breach: How an Adversary Leveraged AI to Target a Water Utility’s OT

Dragos has documented a case in which an adversary used AI tools to target the operational technology systems of a water utility. The incident marks a notable shift in how attackers are approaching critical infrastructure, using AI to probe or exploit systems that control physical processes.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
The Guardian — Privacy · · International

UK Biobank has my data, but I’m not worried. I know the benefits are too great to consider pulling out | Polly Toynbee

A dataset from UK Biobank — a large longitudinal health research repository — reportedly appeared for sale on Alibaba's platform in China, prompting concern among researchers and a warning from UK Science Minister Patrick Vallance that further such attempts are anticipated. Columnist Polly Toynbee argues the research value of such studies outweighs the risks.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
The Guardian — Privacy · · International

More private health records of UK Biobank volunteers appear on Chinese website

Additional confidential health records from UK Biobank's 500,000 volunteers have appeared for sale on Alibaba following last week's initial breach, with Science Minister Patrick Vallance confirming the government is coordinating with Chinese authorities to remove the listings and anticipating further exposures.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
The Guardian — Privacy · · International

Some Interrail travellers told to cancel passports as hacked data posted online

Eurail, the company behind Interrail passes, has disclosed that personal data from a December breach affecting around 300,000 travellers — including passport numbers, names, addresses, phone numbers, and dates of birth — has appeared for sale on the dark web. Some affected customers are now being advised to cancel and replace their passports.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Enforcement
The Markup · · International

Following Markup investigation, Congress finds data brokers cost consumers tens of billions of dollars

A congressional investigation, prompted by a Markup inquiry, estimates that data broker security breaches have resulted in roughly $20 billion in consumer identity theft losses. Several major brokers have responded by pledging to simplify the process for individuals to remove themselves from their databases.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
← Prev Page 21 of 21