Reading view

There are new articles available, click to refresh the page.

KR: 3Pro TV Data Breach Exposes 460,000 Records, Including 2,979 Bank Accounts

Park Hyo-jung reports: More than 460,000 pieces of personal data, including bank account and credit card information, were exposed in a breach at South Korean financial media outlet 3Pro TV. E-Broadcasting, the company that operates 3Pro TV, posted a notice on the outlet’s website saying it had confirmed that “an external actor illegally accessed the...

Source

US cloud ‘kill switch’ is as dangerous as ransomware, European businesses fear

Emma Woollacott reports: European firms are more concerned about a potential US government-imposed ‘kill switch’ for cloud services than almost anything else. In a survey of 1,500 businesses in the UK, France, and Germany, Proton found that with many having built their operations around a small number of US-based providers, they’re worried that access to those platforms could be...

Source

Dutch retailer Bol follows De Bijenkorf in warning of data breach as leaked data appears on dark web

The NL Times reports: Online retailer Bol has warned customers about a data breach involving one of its logistics partners. The company said unauthorized parties accessed the partner’s systems, but emphasized that Bol’s own systems were not affected. Even so, some customer information may have been viewed or copied, the company said in a statement....

Source

AU: Updoc patients notified of security breach where personal information may have been stolen

Emma Kirk reports: Updoc patients have been notified their personal information may have been accessed in a security breach. The website is used for 24/7 telehealth services across Australia. Customers were advised there was a “brief period of unauthorised access to a third party system” where hackers had access to names, email and postal addresses...

Source

Swiss federal IT office hit by cyberattack

SwissInfo.ch reports: Following a cyberattack on the SharePoint servers operated by the Federal Office of Information Technology, Systems and Telecommunication (FOITT), access via the internet has been blocked for people outside the federal administration. Around 200 accounts were compromised in the incident. There are no indications of any further data breaches. The unknown attackers are...

Source

KR: Seoul lawmaker criticizes 5,000-won compensation for 4.62 million-person data breach

The Herald Business reports: Seoul Facilities Corp. has drawn criticism over its plan to offer 5,000 won [$3.50 USD] per affected user in response to a personal data breach involving about 4.62 million people, with questions mounting over whether the compensation is adequate. Seoul Metropolitan Council member Im Gyu-ho of the Democratic Party of Korea...

Source

Singapore’s PDPC finalizes guidance on the use of personal data in generative AI

Charmian Aw, Ciara O’Leary, and Florence Seow of Hogan Lovells Cadwalader write: Singapore’s Personal Data Protection Commission (“PDPC”) has issued its final Advisory Guidelines on Use of Personal Data in Generative AI (“Guidelines”), marking a significant development in Singapore’s AI governance framework. The Guidelines provide long-awaited clarity on how the Personal Data Protection Act 2012...

The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.

Miguel Gomez reports: The biopharmaceutical company Diater, founded in Madrid in 1999, has appeared on the list of victims that the ransomware group DeadLock is disseminating on the dark web. The intrusion affects a company that manages particularly sensitive information of patients and healthcare professionals. The contrast lies in the type of data compromised and...

Source

AU: GO2 Health medical clinic in Brisbane waited almost three months to alert patients it was hacked

Will Murray reports: Another medical clinic has revealed it has been targeted by hackers, less than a week after Partnered Health announced a major data breach. GO2 Health in Everton Park, in Brisbane’s north, said the clinic’s main email mailbox was accessed in April after a phishing attack. It wasn’t until almost three months later...

Source

Ransomware in Italy: RedACT report sheds light on an evolving threat environment

SuspectFile has published a great interview with the people behind RansomNews.online: Within this context, the first RedACT H1 2026 report, published by ransomNews.online, represents a valuable contribution to the analysis of ransomware activity targeting Italy. The project presents itself as a new independent initiative focused on continuously monitoring the ransomware ecosystem through the collection, verification, and analysis...

Source

North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn

Alexander Martin reports: Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations, according to new research released Thursday alongside a joint advisory by four South Korean security and intelligence agencies. The technical report from cybersecurity firm AhnLab details how the state-sponsored North Korean group, widely tracked...

Source

KR: KT Fined 54 Billion Won Over Data Breach via Illegal Base Stations

Two years after a malware incident that was not handled in accordance with South Korea’s requirements, KT has been fined. Lee Jin-seok reports: KT has been fined more than 53.9 billion won [USD $37,630,484.43] over a personal data breach and unauthorized micropayment damages caused by the exploitation of illegal small base stations (femtocells). The government...

Source

Dutch regulator publishes GDPR self-assessment framework for using generative AI

Joke Bodewits and Julian B. Flamant of Hogan Lovells Cadwalader write: On 13 July 2026, the Dutch Data Protection Authority (“AP”) published a practical self-assessment tool (“Tool”) and corresponding guidance document (“Guidance”) on generative AI systems. The Guidance outlines the AP’s expectations under the General Data Protection Regulation (“GDPR”) across the generative AI lifecycle, while...

UK court rejects Bahrain immunity claim in spyware case

Suzanne Smalley reports: The United Kingdom’s Supreme Court ruled Monday that Bahrain can’t hide behind state immunity to block a lawsuit filed by two dissidents alleging the government infected their devices with spyware. Saeed Shehabi and Moosa Mohammed allege Bahrain secretly installed FinSpy spyware on their laptops, likely in 2011. Government agents then spied on...

AU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’

Caitlin Powell reports: A male registered nurse from northern Sydney has been charged after allegedly downloading the data of multiple patients. Police received a report on Wednesday, July 22, that a NSW Health employee had allegedly accessed and downloaded patient information without authorisation. Detectives launched an investigation under Strike Force Civic and, after inquiries, searched a home in Frenchs Forest...

Source

Suspect arrested in investigation into sadistic “764” group

From the Dutch Police: In an investigation into so-called online sadistic COM networks, a suspect from North Holland was arrested on Monday, July 20. As a member of the group ‘764’, the suspect allegedly asked girls to cut themselves and write his online username on surfaces such as walls with their blood—known as ‘bloodsigns’. He...

Source

❌