ZeroHour

Search: “data breach”

27 stories in the last 30d

Korea raises data breach fines to 10% of revenue

South Korea's privacy regulator will impose fines up to 10% of revenue for data breaches leaking personal data of 10 million or more people.

South Korea's privacy regulator is sharply raising penalties for data breaches, with fines reaching 10% of a company's revenue. The higher fines take effect Friday for companies found to have leaked personal data of 10 million or more people through intent or gross negligence. The regulator aims to push companies to treat data protection as a preventive investment rather than a routine cost of doing business.

DataBreaches.net · 7d agoPolicy & legal

Delaware Consumer Privacy and Data-Breach Law Updates

Delaware's governor signed HB 380 and HB 381 amending the state privacy act and breach notification law.

On September 2, 2026, Delaware's Governor signed House Bill 380 and HB 381. HB 380 amends the Delaware Personal Data Privacy Act (DPDPA), enacted in 2023 and effective January 1, 2025. HB 381 separately amends Delaware's computer security breach notification law. Joseph J. Lazzarotti of JacksonLewis summarizes the changes.

DataBreaches.net · 3d agoPolicy & legal

FTC rescinds policy requiring health apps to notify customers after a breach

The FTC unanimously rescinded its 2021 policy statement that required health and fitness apps to notify users after health-data breaches.

The FTC voted to rescind a September 2021 Biden-era policy statement that extended federal health-data breach notification rules to health apps, fitness trackers, and connected devices, which had exposed violators to fines of $43,792 per violation per day. The 2021 statement, adopted in a divided 3-2 vote under then-chair Lina Khan, cited HIPAA coverage gaps for consumer health applications. The commission said the statement provided minimal benefit, was superseded by rulemaking, and aligns with the White House deregulatory agenda.

CyberScoop · 7d agoPolicy & legal

French prosecutors confirm arrest of suspected ZeroBytes hacker behind tax cyberattack

French prosecutors arrested an 18-year-old suspected ZeroBytes member tied to a tax authority breach exposing data of 600,000 people.

French authorities arrested an 18-year-old, alias 'ChatNoir,' in the Paris region on Aug. 18 and placed him in pretrial detention two days later over ZeroBytes attacks; a second suspect under 16 was arrested Aug. 26 and released. ZeroBytes claimed attacks on French government agencies, schools and companies starting July 16, including the DGFiP tax authority, which disclosed an August breach affecting data of more than 600,000 people. The suspect was previously under formal investigation for the 2024 Free telecom breach affecting over 19 million customers and for X account takeovers of BFM-TV and RMC linked to the Epsilon collective. Charged offenses carry up to 10 years in prison and a 300,000-euro fine.

The Record · 9d agoPolicy & legal

UK account-hack losses surge as new reporting system exposes hidden cases

UK reported account-hack losses rose 417% to £6.3M in 2025-26, largely because the new Report Fraud system is capturing previously hidden cases.

The City of London Police's first annual assessment reported £6.3 million in losses from hacked accounts in the year ending March 31, up from £1.2 million, with victims rising from 226 to 2,325. The surge coincides with the January launch of Report Fraud, which replaced Action Fraud; 92% of account-hack reports with financial loss were recorded in the second half of the year. Cyber-dependent crime reports rose 34% to 64,608 while ransomware reports fell 25% to 323, which police warn may reflect underreporting.

The Record · 12d agoPolicy & legal

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

U.S. Treasury sanctioned nearly 60 Iran-linked entities, including MOIS-affiliated Mabna Institute hackers behind breaches of U.S. critical infrastructure and millions in crypto theft.

The U.S. Treasury launched Operation Economic Outcast, designating nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, cyber, and digital asset networks. Five sanctioned individuals are members of the Tehran-based Mabna Institute indicted last week; three allegedly breached and exfiltrated data from U.S. energy, defense, healthcare, IT, and financial organizations since late 2023. TRM Labs traced roughly $16.8 million across 30 wallets tied to the members, and the State Department announced a reward of up to $10 million. The action follows Iranian hacking of FBI Director Kash Patel's email and attacks on over 30 U.S. water and wastewater utilities.

The Hacker News · 22d agoPolicy & legal in the wild

Risky Bulletin: Russia starts blocking DoH and DoT

Russian users report blocks on DoH and DoT servers, including Cloudflare 1.1.1.1 and Google 8.8.8.8, in an apparent censorship crackdown.

Russian internet users began reporting failures connecting to DNS-over-HTTPS and DNS-over-TLS servers, suggesting a government crackdown on the two privacy protocols. The blocks reportedly cover Cloudflare's 1.1.1.1 and Google's 8.8.8.8 resolvers; Roskomnadzor has not officially confirmed the action. The agency tested a similar block in March on Beeline's network and had named DoH for blocking as early as 2021. The bulletin also briefly notes state-sponsored phishing of EU officials, a DDoS against Norway's Digdir, the ReliaQuest/ShinyHunters dispute, and older ransomware and breach disclosures.

Risky Business News · 22d agoPolicy & legal1

France Establishes New Government-Focused Cyber Incident Response Unit

France created REACTIV, an ANSSI-led interministerial cyber incident response unit for state services, after the DGFiP breach exposed up to 678,000 taxpayers.

ANSSI announced REACTIV (Interministerial Response & Action against Data Breaches) on September 7, a dedicated incident response capability for French state services. It lets ANSSI require ministries to take urgent protective measures for citizens' data and lead centralized technical crisis communications during attacks on state services. The move follows the DGFiP tax authority attack that exposed data of 350,000 to 678,000 taxpayers, after which the Prime Minister ordered an extensive audit of ANSSI. Two suspects aged 16 and 18 from the ZeroBytes hacking group were arrested in late August.

Infosecurity Magazine · 8d agoPolicy & legal

CISA review makes the case for eliminating vulnerability classes

CISA's FY2024-2025 vulnerability review urges eliminating recurring vulnerability classes, finding 41.5% of 2025 KEV entries map to persistent 'stubborn weaknesses'.

CISA's Vulnerability Review for fiscal years 2024 and 2025 found most compromises stemmed from opportunistic exploitation of known, exposed vulnerabilities rather than nation-state zero-days or advanced tradecraft. The review found 41.5% of 2025 KEV catalog entries map to 'stubborn weaknesses' - injection flaws, improper input validation, memory-safety failures, path traversal and broken access control - recurring on the CWE Top 25 since 2019. CISA advocates Secure by Design practices, vulnerability class elimination, and buyer-driven 'Secure by Demand' contract requirements, while warning that AI-enabled vulnerability discovery will soon accelerate exploitation.

Help Net Security · 16d agoPolicy & legal

Risky Bulletin: Russia tells data centers to deploy drone defenses

Russia ordered data center operators to deploy drone strike defenses under a Putin decree allowing temporary state takeover of unprotected critical infrastructure.

The Russian government instructed data center operators to deploy protections against drone strikes under a presidential decree signed by Putin that allows temporary state administration of critical infrastructure operators failing to defend against Ukrainian hacks and drone strikes. Although data centers are not formally critical infrastructure in Russia, the decree applies to them because other sectors depend heavily on cloud services; Russia has more than 180 data centers, over 80% in the European region within range of Ukrainian strikes. The digest also reports a Dropbox breach affecting nearly 5,000 accounts via the Lenovo ID integration, spyware attacks on at least 14 Serbians using NoviSpy or Pegasus, and a password recovery attack targeting hundreds of thousands of X accounts tied to the new X Money service. Other items include a 14-hour compromise of Coder's Cloudflare infrastructure delivering malicious Terraform modules, donor data breaches at Davayte and You Are Not Alone via the Stripe/WooCommerce integration, a $2.5M Aquifer crypto heist, and a TVING breach exposing data of almost 40 million accounts.

Risky Business News · 13d agoPolicy & legal

Grindr settles HIV status data-sharing lawsuit for $35 million

Grindr agreed to pay about $35 million to settle a UK privacy suit alleging it shared users' HIV status and sensitive data with advertisers without consent.

The claim, brought by London firm Austen Hays on behalf of roughly 12,000 UK users, alleges Grindr breached privacy and data-protection laws during a period ending in early 2020, when it was owned by Beijing Kunlun Tech. Shared data may have included ethnicity, HIV status, last HIV test date, and PrEP use. Per an SEC filing, Grindr will make two payments of £13 million (totaling about $35 million), one by December 31, 2026 and one by March 31, 2027, without admitting liability. The settlement follows a Norwegian Data Protection Authority enforcement finding over ad sharing without a valid legal basis.

Malwarebytes Labs · 9d agoPolicy & legal

FTC Withdraws Obsolete Policy Statement

The FTC rescinded its 2021 policy statement that applied the Health Breach Notification Rule to health apps and connected devices collecting consumer health data.

The Federal Trade Commission formally rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. The statement had purported to apply the FTC's Health Breach Notification Rule to health apps and connected devices that collect consumer health information. The Commission considers the statement obsolete following its 2024 update to the Health Breach Notification Rule.

DataBreaches.net · 7d agoPolicy & legal

TikTok Settles U.S. Child Privacy Case for $400 Million

TikTok will pay $400 million to settle U.S. DOJ/FTC claims that it violated COPPA by collecting data from children under 13.

The U.S. Department of Justice announced a $400 million settlement with TikTok and ByteDance resolving a 2024 lawsuit over violations of the Children's Online Privacy Protection Act (COPPA). TikTok will pay $300 million immediately and $100 million upon entry of an order vacating a prior consent decree against its predecessor Musical.ly; it is one of the largest recoveries ever obtained in a COPPA case. The DOJ and FTC, filing in California, alleged TikTok knowingly allowed children under 13 to create accounts and illegally collected data via Kids Mode. TikTok was previously fined €345 million by Ireland's Data Protection Commission in 2023 for GDPR breaches involving children's data.

Security Affairs · 24d agoPolicy & legal

Grindr Settles UK Data Privacy Claims for £26m

Grindr will pay £26m ($35.2m) to settle UK group claims alleging unlawful sharing of sensitive data, including HIV status, before 2020, without admitting liability.

The settlement, reached on September 2 and disclosed to the US SEC, covers roughly 12,000 claimants represented by Austen Hays over the free app's 2016–2020 data practices when Grindr was owned by Chinese conglomerate Kunlun. Grindr will pay £13m by December 31, 2026 and £13m by March 31, 2027, and continues to dispute the allegations; the agreement contains no admission of liability. The claims concerned sharing HIV status, PrEP use, ethnicity, and sexual orientation data with analytics providers Apptimize and Localytics without adequate consent. Norway's data protection authority fined Grindr €6.5m in 2021, and the UK ICO reprimanded the company in July 2022.

Infosecurity Magazine · 9d agoPolicy & legal

Risky Bulletin: Two TeamPCP members arrested in Australia

Australian Federal Police arrested two alleged TeamPCP members behind supply-chain worm attacks that stole over 500,000 credentials from compromised open-source libraries.

The AFP arrested alleged TeamPCP leader Ruben Thomson, 21, and Louis Gaebler, 23, near Perth; both were charged and remain in custody. The group inserted a self-spreading credential-stealing worm into open-source projects including Trivy, KICS, LiteLLM, and Telnyx, harvesting more than 500,000 credentials used for network access, ransomware, extortion, and sales. About 78,000 tokens and secrets from nearly 2,200 organizations leaked online last month, and the FBI supported the investigation that began in April.

Risky Business News · 20d agoPolicy & legal in the wild1

US charges Iranians for sprawling hacking campaign on government agencies, universities

DOJ indicts 17 Iranians tied to Mabna Institute IRGC hacking-for-hire campaign that stole 31TB from universities, agencies, and UN organizations.

The U.S. Justice Department unsealed a 14-count superseding indictment charging 17 people linked to the Mabna Institute, allegedly operating on behalf of the IRGC, in a campaign running since around 2013. The group breached 144 US universities, 42 US companies, 178 foreign universities, 11 foreign companies, and agencies including the Department of Labor, Federal Energy Regulatory Commission, and Hawaii and Indiana state governments, plus UN organizations such as UNICEF, stealing at least 31 terabytes of academic and proprietary data and about 8,000 professor email accounts. The State Department offered a $10 million reward for five individuals including Behzad Mesri, previously indicted for the $6 million HBO extortion; universities spent roughly $20 million on investigation and remediation.

The Record · 9d agoPolicy & legal 2 sources

Peers ask why UK cyber bill leaves execs off the personal liability hook

UK peers propose amendments to the Cyber Security and Resilience Bill adding personal executive liability and board-level cyber responsibility; government defends fines-only approach.

Baronesses Kidron and Ludford backed amendments to the UK Cyber Security and Resilience Bill that would introduce personal civil liability for senior executives and mandate board-level cybersecurity responsibility, citing NIS2 and financial-sector accountability rules. Cybersecurity minister Baroness Lloyd defended the bill's existing regime of fines up to £17 million or 4% of annual turnover, with governance requirements to come via secondary legislation. Peers also debated the bill's 24-hour and 72-hour incident reporting requirements, with Baroness Harding proposing an additional 14-day intermediate report and a one-month final report.

The Register · Security · 10d agoPolicy & legal

Why APAC Enterprises Need Real-Time Threat Intelligence as Singapore, Malaysia, and Thailand Tighten Cyber Compliance in 2026

Singapore, Malaysia, and Thailand all tightened cyber compliance in 2026, mandating continuous monitoring and rapid incident reporting for critical infrastructure.

Singapore's CSA issued the Cybersecurity Code of Practice 2026 for Critical Information Infrastructure on 29 July 2026, adding board cyber-resilience duties, annual training, and controls on Interconnected Systems, with most obligations effective by 29 July 2027. Malaysia's Cyber Security Act 2024 requires NACSA-licensed providers, audits, and fast incident notification, with fines up to RM500,000 and up to ten years' imprisonment. Thailand's NCSA cloud security standard has been enforced since 10 September 2026, with a Website Security Standard effective 16 September 2026. The vendor article argues detection speed has become a compliance metric driving demand for real-time threat intelligence.

Cyble · 4h agoPolicy & legal

Data Broker Radaris Loses Domains in Privacy Fight

A New Jersey court ordered people-search broker Radaris to transfer radaris.com and a dozen related domains to Atlas Data Privacy over Daniel's Law violations.

On August 26, a New Jersey judge found Radaris failed to defend claims that it violated Daniel's Law, which protects law enforcement officials' personal data and imposes $1,000 fines per ignored removal request. The court ordered radaris.com and more than a dozen related broker domains transferred to plaintiff Atlas Data Privacy Corp. Radaris had delayed litigation using offshore shell entities and previously used a fictitious CEO named 'Gary Norden' in investor-facing press releases.

Krebs on Security · 19h agoPolicy & legal

Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler

Zurich court sentences Ukrainian ransomware developer to 12 years, 9 months for LockerGoga, MegaCortex and Nefilim attacks including Stadler Rail.

Zurich District Court sentenced a 52-year-old Ukrainian to 12 years and 9 months for developing LockerGoga, MegaCortex, and Nefilim ransomware, plus a 10-year ban from Switzerland; the verdict can be appealed. The operations hit over 1,800 victims across 71 countries with losses of several hundred million Swiss francs, including Stadler Rail (2020, $6 million Nefilim demand), Meier Tobler, and Crealogix. Alleged mastermind Volodymyr Tymoshchuk, indicted in the US and tied to at least 250 companies including Norsk Hydro, remains at large with an $11 million FBI bounty.

The Register · Security · 2d agoPolicy & legal

FBI cyber chief worries private sector not sharing enough cyber threat information

FBI cyber chief Brett Leatherman urged companies to share breach information with the bureau as it publishes a victim-focused cyber strategy.

FBI Cyber Division assistant director Brett Leatherman said at the Billington CyberSecurity Summit that private-sector hesitancy to engage the FBI stems from misconceptions, including a belief that shared incident data is passed to regulators. He warned that organizations breached by PRC nation-state actors risk more by handling intrusions alone, since FBI involvement speeds eradication. The bureau published a new cyber strategy Wednesday emphasizing victim aid, adopting a 'share until it hurts' posture on releasing threat intelligence.

CyberScoop · 7d agoPolicy & legal

Risky Bulletin: Dutch intel services to get extensive new powers

Netherlands proposed a bill granting AIVD and MIVD expanded warrantless tapping, faster hacking powers, and forced data disclosure, citing Russia, China, and Iran threats.

The Dutch government introduced a bill greatly expanding surveillance powers of intelligence agencies AIVD and MIVD, allowing up to one year of tapping without pre-approval and simplified hacking operations against 'foreign adversaries'. Agencies could compel Dutch companies or citizens to provide data under threat of charges, share data with the private sector, and oversight bodies would merge into a new CTT board. The bill follows similar overhauls in Ireland, Germany, and France after Russia's invasion of Ukraine. The newsletter also reports Moonwell hacked for $8.7M, a Cosmos EVM bug exploited for ~$3M, ShinyHunters listing McKesson with claimed hundreds of millions of records, and a pro-Kremlin DDoS claim against Norway's government network.

Risky Business News · 17d agoPolicy & legal

25 Years of Mass Surveillance Is Enough

Bruce Schneier and Cindy Cohn argue post-9/11 mass surveillance expanded far beyond its counterterrorism justification and should be reevaluated for costs to rights.

An essay by Bruce Schneier and Cindy Cohn (originally in Lawfare) traces the post-9/11 shift from targeted surveillance to mass collection of telephone and internet metadata. It cites the Section 215 bulk phone records program, struck down in interpretation by the Second Circuit in 2015 and curtailed by the USA Freedom Act, and the NSA's Upstream program under Section 702 of the 2008 FISA Amendments Act, which ended content searches in 2017. The authors note mass surveillance now serves routine law enforcement and immigration actions, with FBI Director Kash Patel confirming purchases of Americans' data from brokers, and private systems like Flock license plate readers and venue facial recognition feeding government access.

Schneier on Security · 2d agoPolicy & legal

Grindr settles privacy lawsuit tied to disclosure of users’ HIV statuses for $35 million

Grindr will pay $35.2 million to settle a UK privacy lawsuit alleging it shared users' HIV status with advertisers.

Grindr agreed to pay 26 million pounds ($35.2 million) in two lump sums to resolve a UK class action alleging it provided advertisers with sensitive user data including HIV status. The suit was filed in April 2024 over conduct before early 2020, when the app was under Chinese ownership, and involved roughly 12,000 class members. Per an SEC filing, the settlement includes no findings or admission of liability, and the company says data was shared in encrypted form with two service providers.

The Record · 7d agoPolicy & legal

What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies

CISA officials outline future plans for the CDM program, emphasizing speed, automation, unified data, and data-driven federal risk management.

Speaking at an Elastic Federal Cyber Defense Breakfast, CISA officials described next steps for the Continuous Diagnostics and Mitigation (CDM) program that supplies cybersecurity tools to federal agencies. Acting deputy program manager Richard Grabowski named velocity, unification, and data-driven risk management as core goals, including a three-year roadmap to expand SIEM-as-a-Service. Federal CISO Mike Duffy urged aggregating demand across agencies, buying outcomes rather than products, and designing acquisition for continuous improvement. CISA's Matt House tied the program's evolution to post-SolarWinds needs for a government-wide common operating picture.

CyberScoop · 1d agoPolicy & legal

UK Government Enables Passkey Login for 23 Million Users to Fight Phishing Attacks

UK Government enables optional passkey login for GOV.UK One Login, offering 23 million users phishing-resistant FIDO authentication.

The UK government has rolled out passkey authentication for GOV.UK One Login, the single sign-on for services like tax, State Pension, and driver's license renewals, available to over 23 million users. Passkeys are device-bound, unlocked via fingerprint, Face ID, or device PIN, and the government reports they are up to eight times faster than password plus two-step verification. During the initial trial over 300,000 users adopted passkeys, with nearly one in ten daily sign-ins already using them, saving roughly £600 per day in SMS costs. The NCSC endorses passkeys as phishing-resistant credentials that cannot be intercepted or reused, and biometric data never leaves the user's device.

GBHackers · 2d agoPolicy & legal

Conti ransomware crew member sentenced to four years in prison

Ukrainian national Oleksii Lytvynenko sentenced to four years in the US for his role in Conti ransomware attacks on at least 12 companies.

Oleksii Lytvynenko, 44, who pleaded guilty in June to conspiracy to commit wire fraud, was sentenced Thursday to four years in prison by the US Justice Department. He joined the Conti ransomware group in September 2021 as an intruder and malware developer, holding stolen data from 12 victims including eight US-based organizations, and prosecutors said co-conspirators extorted roughly $634,000 in Bitcoin from Tennessee victims including government entities. Conti attacked more than 1,000 organizations before disbanding in 2022, with members rebranding into Zeon, Black Basta, and Quantum/Royal/BlackSuit.

CyberScoopupdated · 5d agofirst · 6d agoPolicy & legal 7 sources1