IT Security & Privacy

Europe’s Data Watchdog Moves to Curb Forced Online Accounts as Digital Omnibus Debate Intensifies

Europe’s top privacy regulator wants online shopping to come with fewer strings attached, specifically unnecessary user accounts. At its latest plenary session on Thursday, the European Data Protection Board (EDPB) adopted new recommendations urging e-commerce companies to let people shop without being pushed into creating accounts that vacuum up personal data.

UK Watchdog Hits Adult Website Operator With £1 Million Penalty Over Child Safety Failures

The UK’s online safety regulator is making an example of adult content providers who still allow children to stumble onto explicit material with little more than a checkbox standing in their way. On Thursday, Ofcom announced a £1 million fine against AVS Group, the operator of 18 adult websites, after concluding the company had failed to put “highly effective” age assurance in place, a new legal requirement under the landmark Online Safety Act.

FinCEN Warns Ransomware Payouts Have Surged Past $2.1 Billion in Just Three Years

Ransomware has never been more costly. That’s the message from a new Financial Trend Analysis released Wednesday by the U.S. Treasury’s Financial Crimes Enforcement Network (FinCEN), which found that attackers drained more than $2.1 billion from victims between 2022 and 2024. The report examines ransomware activity by the date of each incident, offering the clearest look yet at how aggressively cybercriminals have scaled their extortion campaigns.

UK Regulator Rebukes Post Office After Horizon Victims’ Information Published Online

The Information Commissioner’s Office (ICO) has issued a formal reprimand to Post Office Limited after its communications team mistakenly uploaded an un-redacted legal settlement document to the organization’s corporate website. The file (containing the names, home addresses, and postmaster status of 502 individuals involved in the landmark group litigation) was left publicly accessible for nearly eight weeks between April and June 2024.

American Express Hit With €1.5 Million Fine in France Over Cookie Consent Failures

American Express has landed in the crosshairs of France’s data protection regulator, which says the company repeatedly ignored rules that give internet users control over how they’re tracked online.

FTC Cracks Down on EdTech Provider After Data Breach Hits Over 10 Million Students

The Federal Trade Commission is taking action against Illuminate Education after investigators found the popular school software provider failed to secure sensitive student records, a lapse that led to a major hack affecting more than 10 million children across the United States.

FCC Backs Away from Earlier Cybersecurity Mandate, Citing Legal Flaws & Industry Progress

The Federal Communications Commission is reversing a cybersecurity action it took earlier this year, pulling back a Declaratory Ruling that the agency now says misread federal law and would not have made U.S. networks any safer. The FCC also withdrew a related rule-making proposal built on that same interpretation.