GRC Report Staff

DeepSeek’s Database Leak Highlights Security Risks in AI

If there’s one thing we’ve learned in the AI gold rush, it’s that innovation often outpaces security. Case in point, DeepSeek, a rising star in the AI space, just found itself in the hot seat after a major security lapse exposed a publicly accessible database filled with sensitive information. And when we say sensitive, we’re talking chat logs, API keys, backend details—essentially, the crown jewels of its operation.

EIOPA’s Sanctions Report: A Compliance Reality Check for Insurance Distributors

Regulators are watching, and they’re not impressed. The European Insurance and Occupational Pensions Authority (EIOPA) has just dropped its latest annual report on sanctions under the Insurance Distribution Directive (IDD), and enforcement isn’t slowing down—it’s accelerating.

SEC & CFTC Extend Compliance Date for Form PF Amendments

If you’ve been navigating the ever-evolving world of financial regulations, you know that deadlines can be a bit of a pressure cooker. Well, the Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC) have decided to offer a bit of a breather. In a welcome move, they’ve extended the compliance date for the amended Form PF, originally due on March 12, 2025, by three months to June 12, 2025.

Spain’s Market Watchdog Takes Aim at X Over Compliance Failures

Spain’s National Securities Market Commission (CNMV) has had enough. The regulator recently announced it is launching sanctioning proceedings against Twitter International Unlimited Company—better known today as the owner of the platform X—for allegedly failing to police financial scam ads featuring unlicensed and previously flagged investment schemes.

FCA Breaks New Ground with First-Ever Fine for MiFIR Transaction Reporting Failures

Regulators have fired their first warning shot under MiFIR, and it’s landed squarely on Infinox Capital Limited. The Financial Conduct Authority (FCA) has fined the firm £99,200 for failing to report over 46,000 transactions, a lapse that could have left market abuse undetected.

KuCoin Pleads Guilty to Unlicensed Money Transmission, Agrees to Nearly $300 Million in Penalties

For years, KuCoin marketed itself as the “People’s Exchange,” a go-to platform for crypto traders worldwide. But behind the sleek interface and global appeal, U.S. authorities say KuCoin was playing fast and loose with the law—allowing billions in potentially illicit funds to flow through its platform with little to no oversight. Now, that game is up.

MGM Resorts’ $45 Million Data Breach Settlement Advances

It’s not every day that the bright lights of Las Vegas dim—not on the Strip itself, but behind the scenes, where ransomware and cyberattacks have been quietly wreaking havoc. MGM Resorts International is now on the hook for a $45 million settlement after two major data breaches in 2019 and 2023 left millions of customers scrambling to secure their personal information. Last week, a federal judge in Nevada gave preliminary approval to the settlement, which aims to bring some measure of relief to affected customers. But does $45 million buy closure for a crisis like this?