The Cambridge Analytica scandal of 2018 is still not quite out of the news yet, as investigations around the world continue to wrap up. Australia's Information Commissioner has agreed to a $50 million AUD privacy settlement over the violations.
The state-sponsored hackers stole unclassified documents during the raid, but little else is known about what they accessed. The attackers appear to have obtained the API key from a third-party vendor called BeyondTrust.
A finalized FTC order directs Marriott and its subsidiary Starwood to implement a robust data security program within 180 days to protect personal information from exposure.
Law enforcement and cyber authorities in the United States and Japan have attributed North Korean hackers to the DMM Bitcoin crypto heist worth about $308 million.
North Korea's new record for stolen crypto, $1.34 billion, represents 61% of the total of about $2.2. billion stolen in 2024. Skilled state-backed North Korean hackers are almost single-handedly keeping numbers above the $1 billion level globally.
Krispy Kreme has disclosed that the December 2024 disruption to its online ordering systems resulted from a cyber attack later claimed by the Play ransomware group.
Italy was one of the first EU nations to take OpenAI and ChatGPT to task over data privacy violations, even banning the app from the country briefly, and it has now issued the bloc's first GDPR fine of this nature to the company.
NSO Group was found to not only have exceeded its legal level of access to the WhatsApp servers and broken the terms of service with its Pegasus spyware, but to also have violated the US Computer Fraud and Abuse Act as well as California state law.
A 2018 Facebook privacy breach incident that first drew complaints just after the GDPR went into force has finally resulted in the issuance of a penalty. The €251 million GDPR fine stems from a flaw in the platform's "View All" feature.
The stolen passwords are for a MoD portal specifically designed to be used safely from home via member personal devices, but it appears the Russian hackers have been targeting the devices themselves and intercepting the credentials.










