Breaches, enforcement actions, and framework updates, tracked as they happen. Every entry links to its primary source. For analysis, see the Journal.
Incident
McKesson Confirms Breach After ShinyHunters Claims 284 Million Patient Records
McKesson · Under investigation
The extortion group ShinyHunters claimed to have stolen roughly 1 terabyte of data, framed as 284 million patient records, through unauthorized access to third-party applications tied to McKesson's Oncology and Medical-Surgical business units. McKesson said the figure reflects rows of raw data rather than unique patients and that it has not yet determined the financial impact.
Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal
Manchester Airports Group · Data published
Attackers who gained access to admin keys exposed in the frontend code of MAG's three airport websites stole names, contact details, vehicle registrations, and millions of parking and lounge booking records. MAG refused to pay the ransom, and the extortion group published the data covering roughly 8.8 million people.
Australian Regulator Closes Inquiry Into Qantas Breach Without Penalty
Qantas Airways / Office of the Australian Information Commissioner · Closed, no penalty
The OAIC closed its preliminary inquiry into Qantas's 2025 third-party breach without opening a formal investigation or taking regulatory action, finding no likely failure to take reasonable steps to protect customer data. The regulator cited Qantas's existing security controls and rapid containment, while noting the decision could be revisited if new information emerges.
NYC Health + Hospitals Breach Exposes 1.8 Million Patients' Records
NYC Health + Hospitals · Under investigation
A breach at an unnamed third-party vendor with system access exposed names, Social Security numbers, government ID numbers, billing and bank data, and medical records including fingerprint and palm-print biometrics for at least 1.8 million people. The intrusion ran from late November 2025 to February 2026 before discovery, illustrating how a single vendor compromise can cascade into a mass health-data breach.
EU Agrees to Delay Key AI Act Compliance Deadlines
European Union (AI Act) · Formally adopted (Reg. 2026/1744, in force July 27, 2026)
EU lawmakers reached political agreement to push back the AI Act's high-risk system obligations: Annex III systems (recruitment, credit scoring, law enforcement, and public-sector use cases) now have until December 2, 2027, and Annex I product-safety-linked systems until August 2, 2028. The AI Omnibus carrying these changes was published in the Official Journal on July 24, 2026 as Regulation (EU) 2026/1744 and entered into force on July 27, 2026, while the August 2, 2026 deadline for AI-generated content transparency rules remains active.
FTC Takes Action Against Match Group Over OkCupid Data Sharing
Match Group / OkCupid · Proposed settlement
The FTC alleged that OkCupid shared users' photos and location data with an unaffiliated third party without consent, then concealed the practice and obstructed the agency's investigation. Under the proposed settlement, OkCupid and Match Group Americas are permanently barred from misrepresenting their data collection, use, and privacy control practices.
NIST Publishes Draft Transit Cybersecurity Framework Community Profile
NIST · Draft, comment period closed
NIST released a draft Community Profile mapping its Cybersecurity Framework 2.0 to public and private transit systems, covering signaling, dispatching, fare collection, vehicle telemetry, and legacy equipment. It is voluntary guidance rather than a binding rule, aimed at helping transit agencies of any size prioritize security work around passenger safety and service continuity.
California's Automated Decision-Making Technology Rules Take Effect
California (CCPA regulations) · In effect
New CCPA regulations took effect requiring businesses to offer opt-outs when automated decision-making technology substantially replaces human judgment, and to keep a human reviewer able to interpret and override the output. The same rules add risk assessment requirements for data sales, sensitive data processing, and significant ADMT-driven decisions, plus a new cybersecurity audit standard defining what counts as reasonable security.
Indiana, Kentucky, and Rhode Island Comprehensive Privacy Laws Take Effect
Indiana, Kentucky, Rhode Island · In effect
Three more US states joined the comprehensive state privacy law landscape on January 1: the Indiana Consumer Data Protection Act, the Kentucky Consumer Data Protection Act, and the Rhode Island Data Transparency and Privacy Protection Act. All three require data protection impact assessments, opt-outs for targeted advertising and data sales, and consumer rights to access, correct, delete, and port personal data, though thresholds and cure periods differ by state. Rhode Island's law is notably stricter, with no cure period before enforcement.
SolarWinds / U.S. Securities and Exchange Commission · Resolved
A federal judge dismissed most of the SEC's claims against SolarWinds and its CISO, Timothy Brown, in July 2024, ruling that ordinary cybersecurity controls fall outside the accounting-controls provisions the agency invoked. The SEC voluntarily dismissed the remaining case with prejudice in November 2025. The case had been closely watched as a test of how far securities law reaches into cybersecurity disclosure and personal liability for security leaders.
Australian Privacy Regulator Sues Optus Over 2022 Breach
Optus / Office of the Australian Information Commissioner · Ongoing
Australia's privacy regulator filed Federal Court civil penalty proceedings against Optus, alleging the telecom failed to implement adequate cybersecurity measures to protect customer data from October 2019 through its September 2022 breach, which exposed roughly 9.5 million Australians' personal information including passport and driver's license numbers. The regulator is treating each affected individual as a separate contravention, carrying penalties of up to AU$2.22 million each.
Qantas Confirms Data Breach via Third-Party Vendor
Qantas Airways · Resolved
Qantas confirmed that a social-engineering attack against a third-party call center platform in early June 2025 exposed the personal data of 5.7 million customers, after initial estimates put the figure closer to six million. The incident became a widely cited example of third-party and vendor risk rather than a direct network intrusion.
Joe Sullivan / United States v. Sullivan · Resolved
The Ninth Circuit Court of Appeals upheld the conviction and sentence of Joe Sullivan, Uber's former chief security officer, for obstructing a Federal Trade Commission investigation by concealing a 2016 data breach and arranging a $100,000 payment to the hackers disguised as a bug-bounty reward. The ruling reaffirms that individual security and compliance leaders can face personal criminal liability for how a breach is handled and disclosed, not just for the breach itself.
EU's Digital Operational Resilience Act Takes Effect
European Union (DORA) · In effect
DORA became directly applicable across the EU, setting binding ICT risk-management, incident-reporting, resilience-testing, and third-party oversight requirements for banks, insurers, and other financial entities. Direct regulatory oversight was extended to critical technology providers themselves for the first time, not just the financial firms that rely on them.
National Institute of Standards and Technology (NIST) · In effect
NIST published CSF 2.0, the framework's first major structural revision since its 2014 creation. The headline change is a sixth core function, Govern, which frames cybersecurity as an enterprise risk that senior leaders should weigh alongside finance and reputation, rather than treating it as a purely technical concern handled downstream of strategy.
Change Healthcare / UnitedHealth Group · Litigation ongoing
A ransomware attack by the BlackCat/ALPHV group against Change Healthcare, a UnitedHealth subsidiary that processes a large share of U.S. medical claims, disrupted pharmacy and billing systems nationwide for weeks. UnitedHealth confirmed paying a $22 million ransom, and the final tally of affected individuals reached 192.7 million by mid-2025, making it one of the largest healthcare data breaches on record.
Marriott International / UK Information Commissioner's Office · Resolved
The UK's Information Commissioner's Office fined Marriott International £18.4 million over a breach of the Starwood guest reservation database that began in 2014 and went undetected for years, following Marriott's 2016 acquisition of Starwood. The fine was substantially reduced from the £99 million initially proposed, reflecting the ICO's evolving approach to calculating penalties.
Equifax agreed to pay at least $575 million, and up to $700 million, to settle with the FTC, the CFPB, and all 50 states over the 2017 breach that exposed the personal data of roughly 147 million people, traced back to a missed software patch. The settlement remains one of the largest data breach penalties ever secured by U.S. regulators.