Ceva Logistics: One Processor, Ten Controllers, and a Notification Chain That Took Five Days
A cyberattack on eight European warehouses run by Ceva Logistics has produced breach reports to the Dutch data protection authority from at least ten ...
27 articles on breach-notification โ privacy laws, security frameworks, and regulatory compliance.
A cyberattack on eight European warehouses run by Ceva Logistics has produced breach reports to the Dutch data protection authority from at least ten ...
CareCloud, a revenue cycle management vendor serving more than 45,000 U.S. healthcare providers, began notifying at least 345,000 individuals in late ...
Attackers were inside Medical Computer Business Services of Augusta, Georgia between 22 and 26 September 2025. The investigation concluded on 28 May 2...
Origin Energy began investigating on 22 July 2026 after an attacker claimed to hold records on two million customers. By 28 July the company confirmed...
When we covered the DentaQuest breach in June, the working figure was 2.6 million people. Notification letters that began rolling out on 17 July 2026 ...
A 13 July 2026 ransomware attack on Nichirei disrupted roughly 140 distribution centres across Japan, affecting food manufacturers, supermarkets, and ...
An intruder was inside the network of Mercadien, P.C., CPAs between 17 September and 9 October 2025. Pinnacle Financial Partners did not determine tha...
Ernst & Young LLP is notifying clients that an unauthorized third party accessed a third-party IT service management platform between 28 March and 12 ...
Lidl notified online shop customers in Germany, Belgium, and the Netherlands that attackers stole personal data from an external IT service provider โ...
An extortion group calling itself Shadowbyt3$ stole roughly 859 MB of Nintendo of America employee data โ including W-9 tax forms and bank statement P...
Conduent Business Solutions told federal regulators on June 4, 2026 that 62,224,658 people had data exposed in a SafePay ransomware intrusion โ the th...
AssuranceAmerica detected intruders in its network on March 17, 2026 โ roughly 24 hours after a credential attack on an employee. Notification letters...
Between May 27 and June 10, 2026, attackers linked to ShinyHunters exploited CVE-2026-35273, a critical Oracle PeopleSoft zero-day, against more than ...
Medtronic has begun notifying individuals that attackers accessed its corporate IT systems between April 13 and 19, 2026, stealing names, dates of bir...
On June 26, 2026, breach disclosures surfaced for MagMutual Insurance, 911 Driving School, and Germany's Atlas Elektronik on the same day. The three i...
In June 2026, attackers used social engineering to break into third-party-hosted business applications at iRhythm Holdings, maker of the Zio cardiac p...
The extortion group ShinyHunters leaked roughly 234 GB of data tied to DentaQuest, the Sun Life-owned dental benefits administrator, exposing names, d...
OCR's four ransomware settlements announced in April 2026 โ totaling $1.165 million across breaches affecting 427,000 individuals โ share one root cau...
May 2026 saw 95 publicly disclosed ransomware attacks across 17 countries, with Qilin and ShinyHunters leading a campaign that increasingly skips encr...
HHS OCR settled with MMG Fusion, LLC for $10,000 following a breach that exposed the protected health information of 15 million patients โ one of the ...
The Oncology Institute disclosed on May 20, 2026 via SEC Form 8-K that a vendor had detected unauthorized access to information systems handling patie...
The May 2026 Instructure Canvas breach exposed names, institutional email addresses, student ID numbers, and private messages across an estimated 275 ...
In January 2026, France's data protection authority fined Free Mobile โฌ27 million and its parent Free โฌ15 million โ a combined โฌ42 million โ for three...
On April 20, 2026, the Everest ransomware gang listed both Citizens Financial Group and Frost Bank on its dark web leak site, claiming to hold 3.4 mil...
On April 22, 2026, Netherlands-based luxury cosmetics chain Rituals confirmed that attackers had accessed its customer membership database, exposing n...
Two high-profile security incidents broke within hours of each other on April 19โ20, 2026. Both involved AI platforms. Both exposed real customer data...
Data breach fines can reach up to 4% of global revenue under regulations like GDPR, LGPD, and PIPL. This analysis examines fine determination factors,...