GRC Report Staff

Chick-fil-A Says Credential-Stuffing Attack May Have Exposed Customer Data Across 10 States

A Chick-fil-A One account contains more than reward points. It can also hold payment methods, gift card balances, and enough personal information to make it worth trying a password that worked somewhere else. That, according to breach notification letters first reported by BleepingComputer, is what happened in June, when attackers used credentials stolen from an unrelated source to gain access to a limited number of customer loyalty accounts. The campaign did not depend on breaking into Chick-fil-A's systems. It depended on customers reusing passwords.

TAB Pays $1.76 Million After Australian Regulator Finds Widespread Telemarketing & Spam Breaches

The Australian Communications and Media Authority found that Tabcorp Holdings' wagering business repeatedly breached Australia's telemarketing rules while marketing to VIP customers. The regulator identified 351 calls made to numbers listed on the Do Not Call Register without consent, 82 calls placed outside legally permitted hours, and nearly 4,000 calls in which TAB failed to properly identify itself, the purpose of the call, or both.

Poland's Privacy Regulator Says Cybersecurity & Data Protection Can No Longer Be Treated Separately

Poland recorded roughly 270,000 cybersecurity incidents last year, according to the country's Personal Data Protection Office. That was a 150% increase over 2024. The agency says it is seeing the same trajectory in reports of personal data breaches.

ASIC Warns Auditors as It Expands Oversight of Australia's Largest Audit Firms

On Wednesday, the Australian Securities and Investments Commission wrote to every registered company auditor in the country with a reminder that reads less like routine regulatory housekeeping than a response to a profession under unusual scrutiny. Trust, ASIC told auditors, has become part of the story. That alone explains why the regulator felt compelled to restate obligations that already exist in law.

Japan Rewrites Its Corporate Governance Code With Boards, Not Box-Ticking, in Mind

Japan has revised the rulebook that shapes corporate governance for its listed companies, but the changes are less about adding new obligations than about changing how companies think about the ones they already have.

NeoGenomics Settles False Claims Allegations Over Referral Arrangements for $9.8 Million

NeoGenomics, the Florida-based laboratory company, has agreed to pay $9.81 million to resolve allegations that it violated the False Claims Act by providing consulting services below fair market value to healthcare providers whose business it hoped to win and by paying independent consultants in ways that rewarded them for generating referrals. The settlement, announced Monday, resolves the government's civil claims and recognizes what happened after the conduct came to light as much as the conduct itself.

KPMG Australia Finds Confidential Client Information Was Misused, Sanctions Seven Staff

KPMG Australia has sanctioned seven employees after an internal investigation concluded that confidential client information was improperly shared inside the firm, a finding that stands in marked contrast to the firm's earlier position that previous inquiries had failed to substantiate wrongdoing.