When did you last hand your driver's license to a rental-car counter, a retail checkout, or a venue door? The scan doesn't disappear after that transaction. It may still exist, and as of last week it may have been for sale.
Ceva Logistics suffered a ransomware attack in September 2025 that it never disclosed. Ten months later, on July 29, 2026, it happened again, this time much bigger, and a former employee's lawsuit says the first attack should have been the wake-up call that prevented the second.
In late June, the Supreme Court ruled that the President can fire the commissioners of the Federal Trade Commission at will. The FTC is the government's main privacy enforcer, and the case looked like a fight over presidential power in Washington. For any company that stores European data on US servers, it is more than that. It quietly weakened the legal ground under those data transfers.
A Pennsylvania bank just filed the same emergency disclosure a company files after a ransomware attack. Nobody broke in. One of its own people had pasted customer records into an AI tool to get a job done faster.
A director sits down the night before a board meeting and asks ChatGPT to help think through a hard call. A company switches on the AI notetaker that now comes built into its meeting software. Both feel like harmless conveniences. Both create a written record the other side in a lawsuit can demand, and no privilege protects it.
On May 26, the FBI issued a flash alert warning that the Silent Ransom Group, an extortion operation also tracked as Luna Moth, has begun sending operatives into US law firm offices posing as IT support technicians. They walk past reception, plug USB drives into workstations, and copy files. No malware. No ransomware encryption. No locked screens. The systems keep running while the data walks out the door. According to BleepingComputer, 38 firms have already had client data leaked, with demands ranging from $1 million to $8 million.
For over a decade, California companies facing data breach lawsuits could ask one question that usually ended the case: can you prove anyone actually viewed the stolen data? On May 14, the California Supreme Court eliminated that defense.
On April 1, the ShinyHunters extortion group social-engineered a Charter Communications employee into handing over their Microsoft Entra (formerly Azure Active Directory) credentials through a voice phishing call. From that single set of credentials, the attacker pivoted into Charter's Salesforce CRM (customer relationship management system) and extracted customer and employee records before Charter detected the intrusion.
California Attorney General Rob Bonta sued Chrome Holding Co., the entity that emerged from 23andMe's bankruptcy, on May 28. The complaint alleges the company failed to protect 6.9 million users' genetic profiles, took five months to detect the breach, paid a ransom to the threat actor while publicly claiming no systems were compromised, and shifted blame to customers for reusing passwords.
Senator Tom Cotton sent a letter to the Department of Justice (DOJ) this week asking it to investigate whether Chinese-controlled last-mile parcel carriers operating in the United States are a national security risk. The story is not the letter. It is the question the letter forces every retailer to answer.
Delta Dental Insurance Company and Delta Dental of New York paid New York's financial regulator $2.25 million last month for a cybersecurity incident. The incident itself was modest. The penalty was driven by a six-month delay in notification. New York's rules require notification of a covered cybersecurity event within 72 hours. Delta Dental detected a webshell in June 2023 and did not notify the regulator until December 2023. The consent order makes the timing the central finding.
Brazil is about to raise the maximum penalty for a data privacy violation tenfold. Brazil's General Data Protection Law (LGPD), passed in 2018 as a close adaptation of the EU's GDPR, has historically been enforced lightly. Brazilian legislators are advancing PL 4530/23, a bill that would raise the maximum LGPD fine from two percent of company revenue to twenty percent. That is five times GDPR's four-percent ceiling. The bill also doubles the per-violation cap to R$100 million (approximately twenty million US dollars). The Brazilian data protection authority, ANPD, published its 2026-27 enforcement priorities this month: artificial intelligence training data, children's data, and public-sector data processing.
Comcast agreed this week to pay $117.5 million to settle a class action over a 2023 data breach that exposed approximately 36 million Xfinity customer records. Individual payouts reach up to $10,000 for documented out-of-pocket losses. The breach happened three years ago. The settlement landed this week. But don't let the timeline mislead you. Class actions now file within days of a disclosure, not months. The litigation machinery is automated. Plaintiff firms monitor SEC (Securities and Exchange Commission) filings and breach notifications in real time. The moment you disclose, the clock starts.
Your outside counsel knows your acquisition targets, your deal timing, and your pricing strategy. Your incident response firm knows your insurance limits, your negotiating position, and your network architecture. Your compliance auditor knows where your security controls are weakest. You handed all of it over voluntarily because the relationship required it.
General Motors agreed on May 8 to pay $12.75 million to settle allegations that it sold the names, geolocation data, and driving behavior of hundreds of thousands of California drivers to data brokers Verisk Analytics and LexisNexis Risk Solutions through OnStar from 2020 to 2024. It is the largest fine in the California Consumer Privacy Act's (CCPA) history. GM made approximately $20 million from the data sales nationwide. The fine consumed nearly two-thirds of the revenue. GM is now banned from selling driving data to consumer reporting agencies for five years.
The Eastern District of New York unsealed a ten-count indictment Thursday against the former CEO and CFO of iLearningEngines. The charge sheet alleges they fabricated "virtually all" of the company's customer relationships and revenue over multiple years. Specific charges include Continuing Financial Crimes Enterprise, securities fraud, and wire fraud.
A tool called Webloc can track 500 million mobile devices in real time. Not through malware. Not through a warrant. Through the advertising data your phone broadcasts every time an app checks for ads.
Chinese AI models now handle roughly 45% of workloads on major AI routing platforms, up from 1.2% in late 2024. In one week in February, they hit 61%. The reason is cost. DeepSeek charges roughly a tenth of what comparable American models cost. Alibaba's Qwen family has been downloaded 700 million times. Developers have created 180,000 derivative versions built on top of those models. This isn't a consumer app trend. It's a shift in the infrastructure layer that software companies build on.
Three research teams published findings in February and March 2026 that shrank the estimated resources needed to break widely used encryption by a factor of 20.
A Greek court just proved what the industry has known for years. Governments are buying commercial spyware and pointing it at the people making decisions they want to influence.