Data Exposure and Breaches

Large-scale data breaches, exposed databases, data broker risks, and breach notification failures.

They Verified Your ID. Then They Kept It.

When did you last hand your driver's license to a rental-car counter, a retail checkout, or a venue door? The scan doesn't disappear after that transaction. It may still exist, and as of last week it may have been for sale.

The Breach Nobody Was Warned About, Twice

Ceva Logistics suffered a ransomware attack in September 2025 that it never disclosed. Ten months later, on July 29, 2026, it happened again, this time much bigger, and a former employee's lawsuit says the first attack should have been the wake-up call that prevented the second.

A Supreme Court Ruling Just Reached Your EU Customer Data

In late June, the Supreme Court ruled that the President can fire the commissioners of the Federal Trade Commission at will. The FTC is the government's main privacy enforcer, and the case looked like a fight over presidential power in Washington. For any company that stores European data on US servers, it is more than that. It quietly weakened the legal ground under those data transfers.

The Breach With No Burglar

A Pennsylvania bank just filed the same emergency disclosure a company files after a ransomware attack. Nobody broke in. One of its own people had pasted customer records into an AI tool to get a job done faster.

Your Chatbot Will Testify Against You

A director sits down the night before a board meeting and asks ChatGPT to help think through a hard call. A company switches on the AI notetaker that now comes built into its meeting software. Both feel like harmless conveniences. Both create a written record the other side in a lawsuit can demand, and no privilege protects it.

The Attackers Walked Into the Law Firm and Plugged In a USB Drive

On May 26, the FBI issued a flash alert warning that the Silent Ransom Group, an extortion operation also tracked as Luna Moth, has begun sending operatives into US law firm offices posing as IT support technicians. They walk past reception, plug USB drives into workstations, and copy files. No malware. No ransomware encryption. No locked screens. The systems keep running while the data walks out the door. According to BleepingComputer, 38 firms have already had client data leaked, with demands ranging from $1 million to $8 million.

"Prove Someone Looked" Is No Longer Your Defense

For over a decade, California companies facing data breach lawsuits could ask one question that usually ended the case: can you prove anyone actually viewed the stolen data? On May 14, the California Supreme Court eliminated that defense.

You Will Be Sued Before Your Forensic Report Is Finished

On April 1, the ShinyHunters extortion group social-engineered a Charter Communications employee into handing over their Microsoft Entra (formerly Azure Active Directory) credentials through a voice phishing call. From that single set of credentials, the attacker pivoted into Charter's Salesforce CRM (customer relationship management system) and extracted customer and employee records before Charter detected the intrusion.

Your Acquisition Just Bought Someone Else's Breach

California Attorney General Rob Bonta sued Chrome Holding Co., the entity that emerged from 23andMe's bankruptcy, on May 28. The complaint alleges the company failed to protect 6.9 million users' genetic profiles, took five months to detect the breach, paid a ransom to the threat actor while publicly claiming no systems were compromised, and shifted blame to customers for reusing passwords.

When Joe's Last Mile Express Gets Breached, You're Holding the Bag

Senator Tom Cotton sent a letter to the Department of Justice (DOJ) this week asking it to investigate whether Chinese-controlled last-mile parcel carriers operating in the United States are a national security risk. The story is not the letter. It is the question the letter forces every retailer to answer.

Regulators Are Clocking the Delay, Not the Incident

Delta Dental Insurance Company and Delta Dental of New York paid New York's financial regulator $2.25 million last month for a cybersecurity incident. The incident itself was modest. The penalty was driven by a six-month delay in notification. New York's rules require notification of a covered cybersecurity event within 72 hours. Delta Dental detected a webshell in June 2023 and did not notify the regulator until December 2023. The consent order makes the timing the central finding.

Brazil's Privacy Fines Are About to Get Bigger Than Europe's

Brazil is about to raise the maximum penalty for a data privacy violation tenfold. Brazil's General Data Protection Law (LGPD), passed in 2018 as a close adaptation of the EU's GDPR, has historically been enforced lightly. Brazilian legislators are advancing PL 4530/23, a bill that would raise the maximum LGPD fine from two percent of company revenue to twenty percent. That is five times GDPR's four-percent ceiling. The bill also doubles the per-violation cap to R$100 million (approximately twenty million US dollars). The Brazilian data protection authority, ANPD, published its 2026-27 enforcement priorities this month: artificial intelligence training data, children's data, and public-sector data processing.

A Breach Three Years Ago Just Cost $117.5 Million

Comcast agreed this week to pay $117.5 million to settle a class action over a 2023 data breach that exposed approximately 36 million Xfinity customer records. Individual payouts reach up to $10,000 for documented out-of-pocket losses. The breach happened three years ago. The settlement landed this week. But don't let the timeline mislead you. Class actions now file within days of a disclosure, not months. The litigation machinery is automated. Plaintiff firms monitor SEC (Securities and Exchange Commission) filings and breach notifications in real time. The moment you disclose, the clock starts.

What Your Law Firm Knows About You

Your outside counsel knows your acquisition targets, your deal timing, and your pricing strategy. Your incident response firm knows your insurance limits, your negotiating position, and your network architecture. Your compliance auditor knows where your security controls are weakest. You handed all of it over voluntarily because the relationship required it.

The Data You Didn't Know You Gave Away Just Raised Your Expenses

General Motors agreed on May 8 to pay $12.75 million to settle allegations that it sold the names, geolocation data, and driving behavior of hundreds of thousands of California drivers to data brokers Verisk Analytics and LexisNexis Risk Solutions through OnStar from 2020 to 2024. It is the largest fine in the California Consumer Privacy Act's (CCPA) history. GM made approximately $20 million from the data sales nationwide. The fine consumed nearly two-thirds of the revenue. GM is now banned from selling driving data to consumer reporting agencies for five years.

When an AI Company Fakes Its Customers

The Eastern District of New York unsealed a ten-count indictment Thursday against the former CEO and CFO of iLearningEngines. The charge sheet alleges they fabricated "virtually all" of the company's customer relationships and revenue over multiple years. Specific charges include Continuing Financial Crimes Enterprise, securities fraud, and wire fraud.

Every Phone in Your Building Is for Sale

A tool called Webloc can track 500 million mobile devices in real time. Not through malware. Not through a warrant. Through the advertising data your phone broadcasts every time an app checks for ads.

The AI Inside Your Software May Already Report to Beijing

Chinese AI models now handle roughly 45% of workloads on major AI routing platforms, up from 1.2% in late 2024. In one week in February, they hit 61%. The reason is cost. DeepSeek charges roughly a tenth of what comparable American models cost. Alibaba's Qwen family has been downloaded 700 million times. Developers have created 180,000 derivative versions built on top of those models. This isn't a consumer app trend. It's a shift in the infrastructure layer that software companies build on.