Incident

McKesson Confirms Breach After ShinyHunters Claims 284 Million Patient Records

McKesson · Under investigation

The extortion group ShinyHunters claimed to have stolen roughly 1 terabyte of data, framed as 284 million patient records, through unauthorized access to third-party applications tied to McKesson's Oncology and Medical-Surgical business units. McKesson said the figure reflects rows of raw data rather than unique patients and that it has not yet determined the financial impact.

Incident

Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

Manchester Airports Group · Data published

Attackers who gained access to admin keys exposed in the frontend code of MAG's three airport websites stole names, contact details, vehicle registrations, and millions of parking and lounge booking records. MAG refused to pay the ransom, and the extortion group published the data covering roughly 8.8 million people.

Enforcement

Australian Regulator Closes Inquiry Into Qantas Breach Without Penalty

Qantas Airways / Office of the Australian Information Commissioner · Closed, no penalty

The OAIC closed its preliminary inquiry into Qantas's 2025 third-party breach without opening a formal investigation or taking regulatory action, finding no likely failure to take reasonable steps to protect customer data. The regulator cited Qantas's existing security controls and rapid containment, while noting the decision could be revisited if new information emerges.

Incident

NYC Health + Hospitals Breach Exposes 1.8 Million Patients' Records

NYC Health + Hospitals · Under investigation

A breach at an unnamed third-party vendor with system access exposed names, Social Security numbers, government ID numbers, billing and bank data, and medical records including fingerprint and palm-print biometrics for at least 1.8 million people. The intrusion ran from late November 2025 to February 2026 before discovery, illustrating how a single vendor compromise can cascade into a mass health-data breach.

Framework Update

EU Agrees to Delay Key AI Act Compliance Deadlines

European Union (AI Act) · Formally adopted (Reg. 2026/1744, in force July 27, 2026)

EU lawmakers reached political agreement to push back the AI Act's high-risk system obligations: Annex III systems (recruitment, credit scoring, law enforcement, and public-sector use cases) now have until December 2, 2027, and Annex I product-safety-linked systems until August 2, 2028. The AI Omnibus carrying these changes was published in the Official Journal on July 24, 2026 as Regulation (EU) 2026/1744 and entered into force on July 27, 2026, while the August 2, 2026 deadline for AI-generated content transparency rules remains active.

Enforcement

FTC Takes Action Against Match Group Over OkCupid Data Sharing

Match Group / OkCupid · Proposed settlement

The FTC alleged that OkCupid shared users' photos and location data with an unaffiliated third party without consent, then concealed the practice and obstructed the agency's investigation. Under the proposed settlement, OkCupid and Match Group Americas are permanently barred from misrepresenting their data collection, use, and privacy control practices.

Framework Update

NIST Publishes Draft Transit Cybersecurity Framework Community Profile

NIST · Draft, comment period closed

NIST released a draft Community Profile mapping its Cybersecurity Framework 2.0 to public and private transit systems, covering signaling, dispatching, fare collection, vehicle telemetry, and legacy equipment. It is voluntary guidance rather than a binding rule, aimed at helping transit agencies of any size prioritize security work around passenger safety and service continuity.

Framework Update

California's Automated Decision-Making Technology Rules Take Effect

California (CCPA regulations) · In effect

New CCPA regulations took effect requiring businesses to offer opt-outs when automated decision-making technology substantially replaces human judgment, and to keep a human reviewer able to interpret and override the output. The same rules add risk assessment requirements for data sales, sensitive data processing, and significant ADMT-driven decisions, plus a new cybersecurity audit standard defining what counts as reasonable security.

Framework Update

Indiana, Kentucky, and Rhode Island Comprehensive Privacy Laws Take Effect

Indiana, Kentucky, Rhode Island · In effect

Three more US states joined the comprehensive state privacy law landscape on January 1: the Indiana Consumer Data Protection Act, the Kentucky Consumer Data Protection Act, and the Rhode Island Data Transparency and Privacy Protection Act. All three require data protection impact assessments, opt-outs for targeted advertising and data sales, and consumer rights to access, correct, delete, and port personal data, though thresholds and cure periods differ by state. Rhode Island's law is notably stricter, with no cure period before enforcement.

Enforcement

SEC v. SolarWinds Dismissed With Prejudice

SolarWinds / U.S. Securities and Exchange Commission · Resolved

A federal judge dismissed most of the SEC's claims against SolarWinds and its CISO, Timothy Brown, in July 2024, ruling that ordinary cybersecurity controls fall outside the accounting-controls provisions the agency invoked. The SEC voluntarily dismissed the remaining case with prejudice in November 2025. The case had been closely watched as a test of how far securities law reaches into cybersecurity disclosure and personal liability for security leaders.

Enforcement

Australian Privacy Regulator Sues Optus Over 2022 Breach

Optus / Office of the Australian Information Commissioner · Ongoing

Australia's privacy regulator filed Federal Court civil penalty proceedings against Optus, alleging the telecom failed to implement adequate cybersecurity measures to protect customer data from October 2019 through its September 2022 breach, which exposed roughly 9.5 million Australians' personal information including passport and driver's license numbers. The regulator is treating each affected individual as a separate contravention, carrying penalties of up to AU$2.22 million each.

Incident

Qantas Confirms Data Breach via Third-Party Vendor

Qantas Airways · Resolved

Qantas confirmed that a social-engineering attack against a third-party call center platform in early June 2025 exposed the personal data of 5.7 million customers, after initial estimates put the figure closer to six million. The incident became a widely cited example of third-party and vendor risk rather than a direct network intrusion.

Enforcement

Former Uber CISO's Conviction Upheld on Appeal

Joe Sullivan / United States v. Sullivan · Resolved

The Ninth Circuit Court of Appeals upheld the conviction and sentence of Joe Sullivan, Uber's former chief security officer, for obstructing a Federal Trade Commission investigation by concealing a 2016 data breach and arranging a $100,000 payment to the hackers disguised as a bug-bounty reward. The ruling reaffirms that individual security and compliance leaders can face personal criminal liability for how a breach is handled and disclosed, not just for the breach itself.

Framework Update

EU's Digital Operational Resilience Act Takes Effect

European Union (DORA) · In effect

DORA became directly applicable across the EU, setting binding ICT risk-management, incident-reporting, resilience-testing, and third-party oversight requirements for banks, insurers, and other financial entities. Direct regulatory oversight was extended to critical technology providers themselves for the first time, not just the financial firms that rely on them.

Framework Update

NIST Releases Cybersecurity Framework 2.0

National Institute of Standards and Technology (NIST) · In effect

NIST published CSF 2.0, the framework's first major structural revision since its 2014 creation. The headline change is a sixth core function, Govern, which frames cybersecurity as an enterprise risk that senior leaders should weigh alongside finance and reputation, rather than treating it as a purely technical concern handled downstream of strategy.

Incident

Change Healthcare Ransomware Attack

Change Healthcare / UnitedHealth Group · Litigation ongoing

A ransomware attack by the BlackCat/ALPHV group against Change Healthcare, a UnitedHealth subsidiary that processes a large share of U.S. medical claims, disrupted pharmacy and billing systems nationwide for weeks. UnitedHealth confirmed paying a $22 million ransom, and the final tally of affected individuals reached 192.7 million by mid-2025, making it one of the largest healthcare data breaches on record.

Enforcement

ICO Fines Marriott £18.4M Over Starwood Breach

Marriott International / UK Information Commissioner's Office · Resolved

The UK's Information Commissioner's Office fined Marriott International £18.4 million over a breach of the Starwood guest reservation database that began in 2014 and went undetected for years, following Marriott's 2016 acquisition of Starwood. The fine was substantially reduced from the £99 million initially proposed, reflecting the ICO's evolving approach to calculating penalties.

Enforcement

Equifax Reaches Settlement Over 2017 Breach

Equifax / FTC, CFPB, and U.S. states · Settled

Equifax agreed to pay at least $575 million, and up to $700 million, to settle with the FTC, the CFPB, and all 50 states over the 2017 breach that exposed the personal data of roughly 147 million people, traced back to a missed software patch. The settlement remains one of the largest data breach penalties ever secured by U.S. regulators.