IT Security & Privacy

Chick-fil-A Says Credential-Stuffing Attack May Have Exposed Customer Data Across 10 States

A Chick-fil-A One account contains more than reward points. It can also hold payment methods, gift card balances, and enough personal information to make it worth trying a password that worked somewhere else. That, according to breach notification letters first reported by BleepingComputer, is what happened in June, when attackers used credentials stolen from an unrelated source to gain access to a limited number of customer loyalty accounts. The campaign did not depend on breaking into Chick-fil-A's systems. It depended on customers reusing passwords.

Poland's Privacy Regulator Says Cybersecurity & Data Protection Can No Longer Be Treated Separately

Poland recorded roughly 270,000 cybersecurity incidents last year, according to the country's Personal Data Protection Office. That was a 150% increase over 2024. The agency says it is seeing the same trajectory in reports of personal data breaches.

EU Fines AliExpress €550 Million Over Digital Services Act Breaches

The European Commission has fined AliExpress €550 million after concluding that the marketplace failed to meet its obligations under the Digital Services Act to assess and reduce the risks associated with illegal, unsafe, and counterfeit products sold through its platform.

Wind Tre Fined €1.7 Million After Data Breaches Exposed Information of More Than 365,000 Customers

Italy's data protection authority has fined telecommunications provider Wind Tre €1.7156 million after finding serious security deficiencies that enabled attackers to gain unauthorized access to company systems and exfiltrate the personal data of more than 365,000 customers. The decision follows an investigation by the Italian Data Protection Authority, known as the Garante per la Protezione dei Dati Personali, into two data breaches that the company reported in February 2025.

Australian Privacy Regulator Ends Qantas Data Breach Inquiry Without Opening Formal Investigation

When hackers gained access to the personal information of roughly 5 million Australians during the 2025 cyberattack on Qantas, the obvious question was whether the airline had failed in its legal duty to protect that data. After nearly a year of preliminary inquiries, Australia's privacy regulator has answered that question, at least for now.

Austrian High Court Upholds €13 Million GDPR Fine Over Political Profiling

Austria's highest administrative court has brought one of the country's most closely watched data protection cases to a close, confirming that the creation and commercial use of inferred political preferences for millions of people violated the General Data Protection Regulation and clarifying several principles that will shape how GDPR fines are assessed in the years ahead.

23andMe Agrees to $18 Million Settlement Over 2023 Genetic Data Breach

The legal fallout from 23andMe's 2023 data breach is now colliding with the company's bankruptcy proceedings. A coalition of 42 state attorneys general announced Tuesday that it has reached an $18 million settlement with the bankruptcy trustee for 23andMe, resolving allegations that the genetic testing company failed to implement reasonable safeguards before a breach that exposed the information of 6.9 million customers worldwide.