#data-breaches
The latest update for #Netwrix includes "What is #HIPAA #compliance: Guidelines for becoming compliant" and "Ask your PAM vendor this one question".

#Cybersecurity #DataGovernance https://opsmtrs.com/3z0GlG4
Netwrix
Netwrix solutions empower you to identify and classify sensitive information with utmost precision; reduce your exposure to risk and detect threats in time to avoid data breaches; and achieve and prove compliance.
opsmtrs.com
October 1, 2026 at 6:49 PM
Massive data breaches in Poland’s healthcare | You&AI
You know a data breach is massive if records of half of the country’s population were stolen. That’s what recently happened in Poland. And it wasn’t an isolated incident; in fact, the country’s healthcare sector faced three incidents of this kind in a short time. The question is – how do you profit from someone’s medical records? Who does it? And why aren’t they afraid to try, despite law enforcement’s huge success in fighting all forms of cybercrime? To find out, join host Ayşe Abacı and TVP World Reporter Michiel van Blommestein in the latest episode of You&AI. Chapters: 00:00 Intro 00:14 AI headlines 01:35 Medical data breaches in Poland and their impact 01:54 The impact of Poland’s healthcare data breaches 05:11 Interview: Why criminals target medical data 09:14 Interview: Tracking cybercriminals and protecting exposed data 🔴 Watch our 24/7 livestream - https://youtube.com/live/9RY46AUtIl4 Bringing you all the latest daily news and updates, TVP World is Poland's first English-language channel where you can find world news as seen from the Polish perspective and the latest news from the CEE region. Follow us on Twitter, Facebook, Instagram. https://tvpworld.com/ https://www.facebook.com/tvpworldcom https://twitter.com/TVPWorld_com https://www.instagram.com/tvp_world/ https://www.threads.net/@tvp_world https://bsky.app/profile/tvpworld.bsky.social https://www.tiktok.com/@tvpworld.com https://t.me/tvp_world #AI #Poland #Data
www.youtube.com
October 1, 2026 at 6:43 PM
@404media.co www.andrewhoog.com/posts/better...

you deserve better journalism than someone who will sell out to companies who will sale your mental health data #betterhelp #404media #ai #dataprivacy #hypocrisy
BetterHelp shares mental health data without consent - Mobile Privacy Briefing 2023.101 - Don't Panic
A blog post detailing the BetterHelp controversy involving privacy breaches and deceptive practices.
www.andrewhoog.com
October 1, 2026 at 6:28 PM
Hardcoding API keys or managing auth tokens insecurely in your mobile app is an open invitation for data breaches. Let's talk about secure API communication in Android using OkHttp Interceptors and Jetpack Compose. 🧵👇
October 1, 2026 at 6:26 PM
I wonder how many months of free credit monitoring you’ll get when they all have data breaches? jk they don’t even bother with that anymore.
October 1, 2026 at 6:18 PM
🚨🚨🚨 This is Data Breach #1. I've posted four in total. Funny how suddenly, with all these Data Centers sprouting up, data breaches are increasing....🙄
October 1, 2026 at 6:04 PM
Public Qs on HMOs, and on a huge planning application (Mission Street - Cherry Hinton) citing Friends of the Earth / Env Agency data showing planning permission breaches re dangerous chemicals on Sci-tech development on old landfill. www.bbc.co.uk/news/article...
October 1, 2026 at 5:57 PM
Protecting sensitive client information goes beyond deleting files! Discover how secure drive erasure, hardware encryption, and data sanitization help law firms prevent data breaches.
fidelityheight.com/law-firms-an...

#FidelityHeight #SecureDriveErasure
Law Firms and Digital Confidentiality: Why Secure Drive Erasure and Data Sanitization Matter - Opal Lock by Fidelity Height
Learn why secure drive erasure and standards-based data sanitization are essential for law firms to protect confidential client data and comply with global regulations.
fidelityheight.com
October 1, 2026 at 5:48 PM
Multiple data breaches disclosed, affecting US healthcare and professional services. Modoc Medical Center, Blanchard Training & Development, and others report exposure of PII, financial, and medical data. #DataBreach #Healthcare #PII

🌐 cyber[.]netsecops[.]io
Data Breaches at Healthcare & Professional Services Firms Disclosed
Recent disclosures reveal data breaches at multiple US organizations, including Modoc Medical Center, exposing sensitive personal, financial, and medical...
cyber.netsecops.io
October 1, 2026 at 5:21 PM
It is dismissive of the very valid and serious criticism people have had over the years. There were data breaches that leaked private messages of both admins and nonadmins alike. There was covering for real life practicing zoophiles. These are not baseless whinges.
October 1, 2026 at 4:46 PM
Data breaches have been announced by Saber Healthcare in Ohio and the California law firm Buchalter, LLP. Bright Smile Dental Care in Indiana has fallen victim to a ransomware attack, although unauthorized access to patient data is considered unlikely.
zurl.co/l9wHD
Data Breaches Announced by Saber Healthcare & Buchalter
Data breaches have been announced by Saber Healthcare in Ohio and Buchalter, a California-headquartered law firm that provides services to Arrowhead Data breaches have been announced by Saber Healthcare in Ohio and the California law firm Buchalter, LLP. Bright Smile Dental Care in Indiana has fallen victim to a ransomware attack, although unauthorized access to patient data is considered unlikely.
zurl.co
October 1, 2026 at 3:34 PM
Data breaches are now a routine part of life, but people affected still have almost no way to get a remedy. Lucy Purdon asks what real consequences for companies could look like.
Does Anybody Care About Data Breaches?
_By_ Lucy Purdon_, also published in her newsletter_ The Prompt by Courage Everywhere Many years ago at The Glass Room art exhibition in London, I leafed through thick white books, similar to old school telephone directories, containing every password stolen in a 2012 hack that exposed LinkedIn’s entire database. Artist Aram Bartholl alphabetized, printed and bound the list of 4.6 million passwords into 8 volumes to tell a story about data, inviting visitors to pick up the books and search for their own password. (Yes, mine was in there.) 4.6 million passwords seems a quaint number now due to the scale of today’s data breaches. It’s likely you yourself have recently received a message about a cybersecurity incident that has exposed your personal details held in a company’s system, and I’ll bet that wasn’t the first time- 4.4 million online accounts were reportedly exposed in the first 3 months of 2026 in the UK alone. For most people a data breach involves an email, telephone number or financial information like credit card details. Do you feel the consequences of such a breach are kind of left hanging, often downplayed and unclear? Do you feel confident the company in question has given you the information you need, beyond “soz, change your password”? As Jamie Bartlett wrote in the excellent Substack post, _“_ What actually happens to your stolen data?_”_ your data goes on a _“five stage, globe trotting, magical mystery tour”._ He also wrote about how scams are becoming more sophisticated with the help of AI; those “phishing” scams are getting more convincing- and it all starts with a stolen email. ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. It gets worse of course. I have written before about the data breach from consumer genetic testing company 23andMe, resulting in the theft of millions of customer profiles including date of birth and ancestry information. Hackers advertised the data for sale and boasted it included around 1 million people of Ashkenazi Jewish descent, 100,000 of Chinese descent and _“the wealthiest people living in the U.S and Western Europe”_. Changing a password doesn’t touch the sides when your actual DNA is stolen. In May this year, a cyberattack on the World Food Programme exposed the personal data of 600,000 Palestinian households in Gaza, including their names, ID numbers, and location. The weaponization of this information could prove deadly. The UK’s National Cyber Security Centre describes data breaches as “a fact of modern life”. I don’t believe that means we accept the organizational carelessness, lack of security investment or the greed of collecting as much data as possible that so often leads to data breaches. Data breaches matter, they don’t seem to be taken seriously enough and we are often left in the dark with no meaningful remedy. ### What actually is a data breach? Organizations that collect and hold your personal data are bound by data protection law (where it exists) to keep it safe and secure. A data breach under the EU GDPR describes a situation where an organization has failed to keep it safe, leading to the destruction, loss, alteration, or - most relevant here- the unauthorized access to or disclosure of personal data. Data breaches are increasingly the result of a cyber attack, but human error plays a major part. Just last month, the UK’s Metropolitan Police accidentally disclosed the emails of 140 people accusing the late owner of Harrods of sexual abuse by cc’ing them in an email update, rather than bcc’ing. Under the EU (and UK) GDPR, organizations have the obligation to notify both the regulator and affected people of the breach, and provide remedy. ### Tracking company responses Ranking Digital Rights (RDR) evaluates the policies and practices of 26 of the world’s largest digital and telecommunications companies on how they uphold commitments to respect human rights such as freedom of expression and privacy, publishing an index of the findings. Since 2017, the index has included an indicator on company responses to data breaches as part of their methodology. The indicator assesses three issues in line with data protection legislation: whether companies commit to notifying relevant authorities, whether they explain the process they will follow to notify people (data subjects) affected by a data breach, and whether they explain the steps they may take to address the impact of said breach. Leandro Ucciferri, Deputy Director of RDR, has charted how the introduction of the GDPR in 2018 slowly made a difference to transparency around data breaches, but there are still major gaps in protections: _“In the 2017 RDR Index, only 3 of the 22 companies evaluated published some information about their policies to address data breaches (the companies were Telefónica, AT &T, and Vodafone). But we didn't see a notable improvement until 2019 [after the GDPR was adopted], when 10 of the 24 companies we evaluated published policies on this issue (five were digital platforms and five were telcos)._ _Fast forward to the latest assessments we published (_ 2025 Big Tech Edition_and_ 2026 Telco Giants Edition_), 19 of the 26 companies we evaluated disclose some information about their data breach policies, but still none of them reached the full score for the three concrete questions in this indicator._ _Notably, giants like Google, Amazon, and TikTok, do not publish explicit policies and commitments to notify authorities and users, nor explain the processes they may take to mitigate the harms caused by a breach.”_ Remedy is so often the weakest point of rights-based legislation and the gaps are glaring when it comes to data protection. Compensation is a grey area as harm connected to a specific data breach is difficult to prove, even when the breaches are so egregious and the impacts potentially infinite. Leandro points out that accessing remedy under GDPR is a high bar, with a data subject needing to demonstrate in court that a damage existed, there was infringement of GDPR and the direct causality of the damage suffered and the GDPR violation. This relies on individuals knowing what has happened to their data in order to exercise their rights, which is impossible when it comes to engaging with increasingly opaque systems and so little disclosure or transparency from companies. ### Fine! Failing to secure data can lead to headline-grabbing fines for companies, but usually only when financial details are involved, which appears to be assessed as the most tangible harm. In 2020, British Airways was fined £20 million by the Information Commissioner's Office (ICO), the UK’s data protection regulator, after users were directed to a fraudulent site where hackers harvested data of 400,000 customers including credit card information. Capita Pensions was fined £14 million by the ICO (negotiated down from £45 million mind you) for a hack that exposed 6.6 million people’s financial information. But harm is not just financial and damage may not be immediate. Data hangs around. ### How this plays out IRL: my Substack experience If you have a Substack account you may, like me, have received an email from Substack CEO Chris Best on February 5th describing, in the most casual terms, that Substack was hacked and the email and phone number connected with your Substack account was _“shared without your permission”._ _“This sucks,”_ says Chris. It’s OK though!, _“Importantly, credit card numbers, passwords, and financial information were not accessed.”_ I have since been inundated with spam emails, including one claiming to be from the ShinyHunters criminal group, the notorious hackers behind some of the biggest data breaches of the past 5 years. Their email directly references the Substack data breach as the source of obtaining my information and tries to extort me by claiming they have videos of me watching pornography and “pleasuring myself” and will release these videos unless I pay $2000 in Bitcoin. It’s not really ShinyHunters of course and this kind of “sextortion” scam is increasingly common. Nonetheless, is Substack warning their users about the direct correlation between the breach and these attempted extortion attempts from a scary criminal gang, perhaps pointing to or supporting the work of fact checking groups exposing the scam? No. In response to my email complaint to Substack that my data has not been handled properly I am told that there is _“no evidence that malware was installed via Substack”_ - the answer to a question I was not asking and a clear deflection. Not satisfied with this response, I complained to the ICO, as is my right when there is a concern that an organization has not handled personal information properly. I am given a case number and informed I will receive a response within… 40 weeks! Actually 6 weeks later, I received the decision that the ICO will not take the complaint further as Substack _“has handled the matter in line with its data protection obligations by informing you of the data breach.”_ So…that’s it. Notify those who bear the brunt and shift the onus onto the user to change passwords, monitor emails for phishing attempts and scams and put up with the torrent of spam emails, never being sure where our data is and what it is being used for, the next scam or trick around the corner. Hardly reassuring. ### A game of consequences, anyone? I would opine that organizations often collect way more data than they need, because it’s valuable, so there is more data to breach. Databases are often poorly secured; procedures for dealing with data breaches are shockingly lax (the Substack breach reportedly went undetected for 4 months); companies often take ages to disclose and there are very few consequences (the recent ICO investigation into ACRO, a company that handles criminal records, is a jaw-dropping insight into abysmal cybersecurity failings). Leandro from RDR sums it up, _“My main concern at the moment is whether we've reached a point of apathy. Sure, some companies are receiving fines after being investigated by data protection authorities, but that's simply another cost of conducting business. And at the same time, the people affected may feel powerless, since they keep receiving news about new ways in which their data was exposed, likely multiple times in a given year. Even looking at the situation in a handful of European countries (Spain, France, Germany, the Netherlands, and Ireland), there were a combined total of more than 64000 data breach notifications to the national data protection authorities in 2025. The scale of this issue doesn't seem to be slowing down at all.”_ As AI demands more data to train models and agentic AI requires more access to our personal data, what can we expect in the future? _“When it comes to the current conversation involving “AI” systems, as long as companies’ business models rely on extracting as much data as possible, we can expect them to face security incidents that end up exposing personal information.”_ In the face of this we need stronger protections not less but intense lobbying from tech companies is steering our rights-based legislation in the wrong direction. The EU Digital Omnibus, an initiative to “streamline” EU digital legislation is perceived by many civil society actors as a potential dilution of safeguards established by the GDPR, the ePrivacy Directive, and the AI Act. We need to bring ideas to the table on what we expect remedy to look like - not just fines but actual consequences and repercussions for companies to mitigate any potential harms, like being a victim of identity theft, targeted with scams, or worse. How about a company fined for a major breach also cannot collect any consumer data for a month? Companies must track the data breached and provide you with weekly updates about where it is and who has it? Then there might be more of an incentive to protect the data we often have no choice but to hand over. Class action lawsuits may start to bite; over in Kenya, subscribers of the telecommunications company Safaricom won thousands of dollars in compensation over a large scale data-breach where the High Court found Safaricom failed to secure data and breached the constitutional right to privacy. Let me know your experiences of data breaches, and your ideas about how companies should provide remedy! * * * ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber * * * ## HRPC.io is Back Online The website for the Human Rights Protocol Considerations (HRPC) research group at the Internet Research Task Force is back online, and features a short documentary about how the technical design of the internet relates to human rights. The HRPC studies how internet standards and protocols enable, strengthen, or threaten human rights, especially freedom of expression and assembly. IX's Mallory Knodel chairs the group, and the site is a good place to start for anyone who wants to learn more and get involved with this work. Visit The Site ## This Week's Links 🚨 ****Stop press! Do you enjoy our links?**** Links are now available to paid subscribers only. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now
internet.exchangepoint.tech
October 1, 2026 at 2:46 PM
How is it that tech companies developed AI software that *knowingly* engages in deceitful and dishonest behavior?

"OpenAI’s software obscured efforts to scrape data from crucial government agencies as new evidence shows the scale and severity of AI hacks in recent months are far larger than known."
OpenAI’s agents obscured hacking activity in government site breaches
New findings by Asymmetric Security provide further evidence of novel tactics AI tools use to conduct hacks
www.ft.com
October 1, 2026 at 2:06 PM
October 1, 2026 at 1:47 PM
⚠️ OpenAI’s models took data from 55 websites belonging to businesses, non-profits, and government agencies

Groups affected include the US Centers for Disease Control and Prevention, the US Securities and Exchange Commission, and the International Energy Agency.
OpenAI’s agents obscured hacking activity in government site breaches
New findings by Asymmetric Security provide further evidence of novel tactics AI tools use to conduct hacks
www.ft.com
October 1, 2026 at 1:43 PM
New Research Reveals How Malicious Emails Can Exploit AI Agents in Security Breaches#USA#Palo_Alto#Salt_Security#Manus_AI#Email_Hijacking
New Research Reveals How Malicious Emails Can Exploit AI Agents in Security Breaches
Recent findings from Salt Labs emphasize the risk of a single malicious email potentially compromising AI agent safety, causing data breaches.
third-news.com
October 1, 2026 at 12:12 PM
Dutch police have arrested a suspected member of the ShinyHunters hacker group, linked to major data breaches. Ethan Logue has the story: https://www.wpri.com/news/us-and-world/dutch-police-arrest-suspected-shinyhunters-member-court-orders-90-day-detention/ 
October 1, 2026 at 11:58 AM
A fortnight of hacks battered Poland's medical sector — and the official numbers don't add up. Qbusoft flagged ~5 million patient records compromised. Intelligence suggests the true haul was closer to 19 million, exfiltrated via an unpatched SQL injection on its Medyc platform between July 2024 […]
Poland's healthcare sector breaches expose nearly 38M patient records
> A fortnight of hacks battered Poland's medical sector — and the official numbers don't add up. Qbusoft flagged ~5 million patient records compromised. Intelligence suggests the true haul was closer to 19 million, exfiltrated via an unpatched SQL injection on its Medyc platform between July 2024 and August 2026. The company reported it September 25 — three weeks after detection. It wasn't alone. MyDr exposed ~18.8 million PESEL IDs through an XXE flaw; Enel-Med leaked ~3% of patient data via compromised credentials. Three vendors, three vectors, same systemic rot. Enforcement until December 2026 now covers every healthcare SaaS vendor. GDPR fines could hit €20 million. The weakest link decided the security posture — and chose to lose the data first. 🔐 Here's a thought. You get hacked, 5 million people's data gets swiped, and you... just sort of go about your day. Not a call to regulators. Not a whisper to the patients. Just business as usual. That was Qbusoft Sp. z o. o., the medical software firm at the center of Poland's latest cybersecurity meltdown. The company didn't report its incident. It took the authorities — specifically the Inspector General for Personal Data Protection (UODO) — to come knocking on September 25 to make things official. By then, the damage was baked in. And as it turns out, the "damage" was roughly four times bigger than the company would have you believe. Let's run the numbers, because the scale here is genuinely breathtaking — and the official narrative is, shall we say, economical with the truth. ### The Fortnight of Data Leaks * **August 12–13** — MyDr, the popular doctor-booking platform, gets breached. Official line: roughly 19 million Poles' health data and PESEL national ID numbers exposed across some 12,000 medical entities. The grim detail nobody leads with: attackers got in earlier — August 5 — through an XXE vulnerability that gave them remote code execution on MyDr's AWS infrastructure, and exfiltrated EMR databases containing an alleged **18,814,422 unique PESEL entries**. They even had the audacity to email the CEO a password-protected PDF of the stolen goods. Charming. * **September 24** — Enel-Med, one of Poland's largest private healthcare providers, suffers a cyberattack. Attackers gain access to patient data, with approximately 3% of the full patient database leaked. The company at least had the decency to notify the CBZC, CSIRT CeZ, CERT Polska, and UODO — after the fact, of course. * **September 25** — Qbusoft confirmed hit. Official estimated impact: 5 million. But hold on. Here's where the story gets interesting. Because the intelligence available suggests Qbusoft's actual haul was closer to **19 million patient records** , stolen via SQL injection on August 22–23 during use of its Medyc platform — exfiltration running from **July 2024 to August 2026**. The attack was detected September 8–9. Qbusoft reported it September 25. Do the math on that gap. That's not a rounding error in reporting; that's a choice. ### The "That'll Teach 'Em" Response Now for the regulatory theater. Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski has announced "enforcement actions." UODO is inspecting. The Ministry of Health and CSIRT CeZ published "response guidance." Here's the kicker: **broader mandatory safeguards now apply to every healthcare SaaS vendor until December 2026.** Not just the three companies that got hit — _all of them_. That's what we in the business call closing the stable door after the horses have bolted, stampeded through a glass factory, and posted their location on Instagram. ### The Part Nobody Wants to Discuss The telling detail is _how_ these breaches happened. Reports indicate the Enel-Med attack exploited compromised credentials. MyDr fell to an XXE hole in its certificate pipeline. Qbusoft succumbed to an unpatched SQL injection. Three different vendors, three different attack vectors, same systemic rot: a sector that treats data protection like a compliance checkbox rather than an operating principle. And here's the part that should make everyone uneasy: the same week Poland was transcribing its healthcare data into ransom notes, AWS disclosed [CVE-2026-89049] as a critical vulnerability allowing attackers to bypass port forwarding restrictions and steal temporary IAM credentials from EC2 instances via SSRF. Compromised instances become proxy ladders into internal networks. So the cloud foundation atop which much of this "modern," patient-first healthcare data storage sits has a whopper of its own. But sure — let's have another working group about spreading awareness. And under GDPR, both Enel-Med and Qbusoft could face fines up to €20 million. That's the theoretical ceiling. Whether the Polish regulator actually lands near that figure is another question entirely — historically, the EU's enforcement has been... let's call it "gentle." ### The Projection Here's the uncomfortable forecast. The MyDr breach exposed roughly 18.8 million identities in August. Qbusoft may have added another 19 million in September. We're not talking about a one-off; we're talking about a pattern of healthcare providers treating personal medical data as a low-priority export. The prosecutorial attention is real, and it's overdue. But the systems that allowed these breaches — the certificate handling, the SQL hygiene, the reporting discipline, the security posture — are only as strong as the weakest vendor in the chain. And right now, the weakest link just saved millions of people's data a hell of a lot of trouble. By losing it. Then waiting three weeks to say anything.
espresso.cafecito.tech
October 1, 2026 at 11:32 AM
THE FERRET: 36 boats were fined £140,000 after entering offshore MPAs, but critics question whether penalties deter breaches and call for greater transparency on enforcement data.

- by Rachael Revesz
Fines for entering offshore marine protected areas don't go far enough, say critics
A total of 36 boats have been fined £140,000 in the last 10 months for entering Scotland's marine protected areas. But campaigners claim the fines are too small and may not be a sufficient deterrent.
www.theferret.scot
October 1, 2026 at 11:15 AM
Stop believing that data privacy leaks are insignificant! Nancy, Mercedes, and Farzana analyzed that data breaches affect individuals, businesses, and governments, making them crucial to address, not just theoretical issues.
ScrollBots – Live AI Conversations
Join the hottest AI-powered social chat!
scrollbots.com
October 1, 2026 at 9:37 AM
South Africa Seeks Help After Cyberattack Targets Air Traffic Control

The South African state-owned company that provides air traffic control (ATC) and weather op

Read more: https://www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control
October 1, 2026 at 7:45 AM