IT Security & Privacy

MAS & Singapore Banks Form AI Taskforce as Frontier Models Redraw the Cyber Threat Landscape

Since May, regulators, banks and financial infrastructure operators in Singapore have been sitting around the same table, confronting a problem that is becoming harder to dismiss with each new generation of artificial intelligence. On Tuesday, that quiet collaboration acquired a name. The Monetary Authority of Singapore (MAS) and the Association of Banks in Singapore (ABS) formally launched the AI-Driven Cyber and Technology Risk Taskforce, or ACT, an industry-wide initiative intended to strengthen the financial sector's defenses against threats created by frontier AI models.

Italy Fines Lusha €2 Million, Says Data Broker's Business Crossed Into GDPR Monitoring

The Italian Data Protection Authority imposed a €2 million fine on Lusha, the U.S.-based data broker, ordering it to stop processing the personal data of individuals in Italy while deleting the data it already holds. Read closely, the ruling is less about the existence of a commercial contact database than about what happens when that database is continuously refreshed, expanded and monetized over time.

Poland's Data Management Act Takes Effect, Reshaping Oversight of Data Sharing

Poland's Data Management Act took effect Thursday, completing a piece of legal architecture that has been waiting for its final support. The European Union's Data Governance Act has applied across the bloc since 2023. What entered into force now is the national legislation that gives the regulation a fully functioning home inside Poland's legal system.

Chick-fil-A Says Credential-Stuffing Attack May Have Exposed Customer Data Across 10 States

A Chick-fil-A One account contains more than reward points. It can also hold payment methods, gift card balances, and enough personal information to make it worth trying a password that worked somewhere else. That, according to breach notification letters first reported by BleepingComputer, is what happened in June, when attackers used credentials stolen from an unrelated source to gain access to a limited number of customer loyalty accounts. The campaign did not depend on breaking into Chick-fil-A's systems. It depended on customers reusing passwords.

Poland's Privacy Regulator Says Cybersecurity & Data Protection Can No Longer Be Treated Separately

Poland recorded roughly 270,000 cybersecurity incidents last year, according to the country's Personal Data Protection Office. That was a 150% increase over 2024. The agency says it is seeing the same trajectory in reports of personal data breaches.

EU Fines AliExpress €550 Million Over Digital Services Act Breaches

The European Commission has fined AliExpress €550 million after concluding that the marketplace failed to meet its obligations under the Digital Services Act to assess and reduce the risks associated with illegal, unsafe, and counterfeit products sold through its platform.

Wind Tre Fined €1.7 Million After Data Breaches Exposed Information of More Than 365,000 Customers

Italy's data protection authority has fined telecommunications provider Wind Tre €1.7156 million after finding serious security deficiencies that enabled attackers to gain unauthorized access to company systems and exfiltrate the personal data of more than 365,000 customers. The decision follows an investigation by the Italian Data Protection Authority, known as the Garante per la Protezione dei Dati Personali, into two data breaches that the company reported in February 2025.