LATEST POST
Carhartt data breach affects 12.9M, half of what ShinyHunters claimed
The Register reports: Workwear and fashion retailer Carhartt’s data breach was about half as bad as ShinyHunters claimed, according to Troy Hunt, who reviewed the data dump before uploading it to his Have I Been Pwned website. Hunt’s HIBP service reported 12.9 million individuals affected by the alleged breach, around half of what ShinyHunters purported […]
‘Close Enough’ Data Breach Notifications Create Exposure
A reminder that the details of states’ data breach notification laws really do matter. A notification that may be satisfactory in most states may be noncompliant in another state and really cost the firm. From attorneys at BakerHostetler: One ruling is not a trend. And there can be unique factors at play in regulatory investigations […]
MCNA Data Breach Settlement Is Offering Up to $2,500 Payouts and Two Years of Monitoring for Millions
The Daily Hodl reports: A proposed class action settlement is offering cash payments and monitoring services to millions affected by a data breach at a health care company. The agreement stems from the Crowe v. Managed Care of North America (MCNA) class action lawsuit filed in the U.S. District Court for the Southern District of […]
“Cognizable damage” required for data breach claims, MA appeals court says in a first
There has been another ruling that makes it harder for plaintiffs in data breach litigation to prove standing. As seen on JDSupra: Helpful guidance for businesses, and for Massachusetts state courts. In 2021, the U.S. Supreme Court held in TransUnion, LLC v. Ramirez that in a suit for damages, “the mere risk of future harm, without more, cannot […]
Fizzle: ShinyHunters’ claimed attack on ReliaQuest went nowhere: ReliaQuest
DataBreaches.net reports: Read ReliaQuest’s blog post.
Iran-linked hackers blamed for cyber-attack that shut down UK power plant
The Guardian reports: Hackers linked to Iran have been blamed for a cyber-attack that caused a British power plant to be temporarily shut down. The incident involved a small-scale energy generator, according to the UK government, which said that at no point was there a risk to the wider energy system. However, it marks an apparent escalation […]
Cognizant Alerts Customers To Potential Data Exposure Following Cyber Breach
IANS reports: IT services firm Cognizant has notified customers of a data breach that occurred on April 21, 2026, which may have exposed personal information, while stating that there is no evidence so far that the data has been misused, as per multiple reports. In a notification sent to affected individuals, the US-headquartered company said […]
500 Hosts, 1 TB and No Negotiation: Anubis Reveals Its Fairlife Attack
SuspectFile provides more details on the previously disclosed cyberattack affecting Coca-Cola’s subsidiary, Fairlife. One week. According to Anubis, that is all the time it allegedly needed to turn a vulnerability in a corporate VPN into full access to Fairlife’s IT infrastructure. One week to get in.One week to move through the network.One week, according to […]
