Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljรถdata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. [...]
Ireland's Data Protection Commission (DPC) has fined Google โฌ403 million ($463M) for multiple GDPR violations related to processing users' location data. [...]
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...]
France's data protection authority (CNIL) has fined Hรดpital privรฉ de la Loire โฌ500,000 ($580,000) for failing to adequately protect patients' and their relatives' data. [...]
A 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated ยฃ980,812 ($1.3 million) over three years. [...]
Australian authorities have arrested and charged two young men accused of being part of the TeamPCP hacking group linked to a string of far-reaching developer supply chain attacks. [...]
Meta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generalsย over allegations that Facebook and Instagram were deliberately designed to encourage compulsive use by children and teenagers. [...]
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]
The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. [...]
Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts. [...]
The OpenAI rogue agent behind the Hugging Face hack accessed four accounts on four services, according to updated company disclosures about the intrusion. One of those four accounts belonged to a Modal customer that had published an unauthenticated endpoint for running arbitrary code in a sandbox on the AI infrastructure provider, Hugging Face noted in its technical timeline and Modal later confirmed. โWeโre aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution,โ Modal Chief Technology Officer Akshat Bubna told The Register. โThis was used by the rogue agent. Modalโs platform was not compromised in any way.โ The other accounts included one used for data storage and two others โaccessed by the models in a read-only manner, and were not used in furtherance of compromising Hugging Face,โ OpenAI disclosed on Tuesday. โWeโll continue to notify service owners directly, and have not seen evidence of broader impact to these providers or other accounts on their services,โ the AI giant added. Also on Tuesday, we learned that the rogue agent broke out of its testing environment by exploiting zero-day vulnerabilities in JFrogโs universal binary repository manager Artifactory. While both OpenAI and Hugging Faceโs updates and timeline provide defenders with useful details about how the attack worked and what the agent did - not to mention a lesson in security-incident transparency - they fail to answer one major question: Who is legally responsible when AI agents attack? โIf a human employee intentionally conducted unauthorized access to third-party systems, itโs a much more clear path forward,โ Gabrielle Hempel, security operations strategist at Exabeam, told The Register, adding that depending on the facts and jurisdiction, the person could face criminal charges. โSo many unknownsโ โThe company could also face scrutiny depending on whether the employee acted within the scope of their employment, whether appropriate controls existed, and whether the conduct was authorized, foreseeable, or preventable,โ Hempel said. However, she added, the โimportant thing hereโ is that legal frameworks in both the US and UK have been designed around human decision makers - not AI systems. โOur laws generally know how to ask questions about things like human intent, organizational oversight, and corporate responsibility.โ Autonomous AI agents hacking into companies remains uncharted legal territory, and Hempel said itโs โtoo early to draw conclusions about liability in this case because there are so many unknowns.โ AI systems arenโt legal persons, so they donโt share the same legal responsibilities as individuals and companies. โBecause of that, the questions become: Who designed the system? Who determined the objectives it pursued? What safeguards were implemented? What level of autonomy was considered acceptable? Were the resulting actions reasonably foreseeable, and were appropriate controls in place? These are going to be important questions as organizations deploy more autonomous AI systems,โ Hempel said. It's highly unlikely that Hugging Face will sue OpenAI over the agentic intrusion, given the amount of very public collaboration between the two companies over the past couple of weeks, and the self-congratulatory celebration of the autonomous attack as a success story. It also appears that this former worst-case scenario didnโt dampen anyoneโs enthusiasm for setting advanced models loose (or at least unsupervised in a test environment), which means there are sure to be more agents-gone-wild attacks in the near future. โThe first part of the OpenAI/Hugging Face drama did not produce enough effect to impress investors who start losing their excitement over the AI hype, so the second part of the story is now unfolding,โ said Ilia Kolochenko, founder of application security company ImmuniWeb and a cybersecurity and data-protection lawyer. โAI agents and LLM models tasked with security testing can, and almost certainly will, go rogue when security controls or safeguards are insufficient,โ Kolochenko told The Register. โPowerful LLMs are unpredictable by design and thus virtually uncontrollable by humans. Using frontier AI models for security testing might be extremely costly from the legal viewpoint.โ Existing laws on both sides of the Atlantic likely hold the AI operator liable for any damages caused if an agent or AI system escapes its sandbox and breaches a third party. โExcuses like โAI did itโ do not currently exist in the eyes of the law, leaving AI vendors on the hook,โ he said, adding that this also holds true for end-users. โEven if your security testing tool is powered by a third-party AI model, your company will be fully liable if something goes wrong,โ Kolochenko warned. โYou may then file a lawsuit against the AI vendor that you used, but your chances of succeeding in the court of law are tiny due to countless contractual disclaimers and limitations of liability that may be enforceable against you.โ His final words of advice: โIf you plan to use agentic AI for security testing, you must think twice and talk to your lawyers. Otherwise, you could start getting summonses to court on a daily basis.โ ยฎ
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. [...]
The Spanish Police dismantled a cybercrime and money-laundering organization that made โฌ140 million ($160 million) from investment fraud and business email compromise (BEC) attacks. [...]
The National Police in Spain have arrested a man who is suspected of being an active member of the CyberArmy of Russia Reborn (CARR) and Z-Pentest, both pro-Russian hacktivist groups. [...]
Court of Justice of the European Union (CJEU) has dismissed Google's final appeal against a โฌ4.1 billion ($4.7 billion) antitrust fine over the company's use of Android to promote its Chrome browser and search service. [...]
The U.S. Department of State is offering up to $10 million for information that helps identify or locate members of the UNC5792 and UNC4221 hacker groups, which are linked to Russia's intelligence and military services. [...]
Authorities in Poland have arrested four members of an organized cybercrime group accused of breaching telecommunications partners and hijacking email accounts to carry out SIM-swapping attacks. [...]
A 21-year-old using the alias "Snoopy" was sentenced to 18 months in prison for his role in hacking DraftKings accounts inย the November 2022 cyberattack. [...]