< ciso
brief />
Tag Banner

All news with #regulatory action tag

406 articles

OT Coalition Urges CISA to Mandate Federal OT Security

🔐 The Operational Technology Cybersecurity Coalition (OTCC) urged CISA to issue a binding operational directive requiring mandatory OT security across federal civilian agencies, citing lack of minimum practices and limited visibility into risks. The report highlights OT in over 8,000 GSA-managed facilities and follows a GAO finding that most agencies missed OMB inventory requirements. The proposed directive would set baselines for asset inventory, segmentation, remote access, configuration, incident preparedness and recovery.
read more →

Italy fines IQVIA €7M for inadequate data anonymization

🔒 Italy's Data Protection Authority fined IQVIA €7 million over insufficient anonymization and data-processing practices affecting about one million patient records. The GPDP found that pseudonymous codes plus detailed health and location data could enable re-identification, and that some records included full personal identifiers. Authorities also cited lack of legal basis, failure to inform patients, and missing retention policies, ordering compliance within 120 days.
read more →

South Korea probes bank breaches amid AI suspicions

🔎 South Korea's Financial Services Commission convened an emergency meeting after a string of cyberattacks affected major banks, including Shinhan Bank, KB Kookmin Bank, and Hana Bank. Authorities confirmed data leaks — reportedly affecting tens of thousands of customers — and launched on-site investigations while coordinating with KISA and other agencies. Financial firms were ordered to inspect externally accessible systems, tighten access controls, share threat intelligence, and submit security inspection results promptly.
read more →

US Sanctions Tren de Aragua Over ATM Jackpotting

🔒 The U.S. Treasury has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for roles in widespread ATM jackpotting campaigns that stole millions from U.S. banks. The designated individuals include alleged Ploutus developer Anibal Alexander Canelon Aguirre ("Prometheus") and six associates, while OFAC cited extensive laundering and international transfers. The Treasury also added seven TRON addresses tied to roughly $6.1 million in inflows to the SDN List.
read more →

Police disrupt KillSec ransomware ring after arrests

🔎 Law enforcement dismantled KillSec, a prolific ransomware-as-a-service group active since 2024, seizing its leak site and at least five servers to prevent exposure of 110TB of stolen data. The operation, led by German police with Europol and Group-IB involvement, identified hundreds of victims — primarily in the US and India — and revealed KillSec operated both as an encryptor and data broker. Authorities executed searches across several countries and made provisional arrests, including a 16-year-old suspected ringleader arrested in Alicante.
read more →

EU Cyber Resilience Act reshapes vendor security baseline

🔒 The EU Cyber Resilience Act mandates 24-hour reporting for actively exploited vulnerabilities and severe incidents affecting products with digital elements, creating an EU-wide product-security law that applies even to non-EU companies. Experts warn the requirement effectively ends manual vulnerability triage, forcing vendors to automate linkage between SIEMs, SBOMs, KEV alerts, asset inventories, and other telemetry. The regulation is expected to elevate secure-by-design practices, test operational resilience, and reshape global technology markets much like GDPR did for data protection.
read more →

Dutch Police Arrest Suspect Linked to ShinyHunters

🔒 Dutch authorities confirmed the arrest of a 24-year-old Amsterdam resident in an investigation into the hacker group ShinyHunters. The suspect is due to appear before the Rotterdam District Court on September 29, 2026, after being taken into custody on September 15. Independent reporting identified the individual as Pepijn van der Stap (aka Umbreon), who previously worked in cybersecurity and was linked to earlier data thefts.
read more →

Dutch police arrest former hacker linked to ShinyHunters

📰 Dutch authorities arrested a 23-year-old convicted cybercriminal, identified by sources as Pepijn van der Stap, on suspicion of aiding the ShinyHunters hacking collective in data thefts and extortion. Van der Stap — previously convicted in 2023 and released in December 2025 — had presented himself as reformed while working in offensive security. Following his detention, ShinyHunters escalated attacks, claiming breaches of the FBI jobs site and extorting other groups, exploiting a PeopleSoft flaw (CVE-2026-35273). Investigations continue into ties between ShinyHunters, a rival teenage operator known as Rey, and recent large-scale data thefts.
read more →

Rydox admin pleads guilty; faces lengthy sentence

🔒 Rydox administrator Ardit Kutleshi pleaded guilty to operating a major illicit marketplace that sold stolen identities, login credentials, credit card data, and cybercrime tools. Arrested in a 2024 international operation that seized the site's domain and servers, Kutleshi was extradited to the U.S. in 2025 and charged with identity theft, money laundering, and related offenses. He faces sentencing in February 2027 and substantial prison time.
read more →

Sweden fines Miljödata over municipal data breach

🔒 IMY, Sweden’s data protection authority, fined IT provider Miljödata SEK 1.8 million ($183,000) after an August 2025 cyberattack exposed personal data of 2.2 million people across municipal systems. The regulator found the company failed to perform adequate checks on newly installed software and lacked automated real-time monitoring to detect intrusions, violating GDPR Article 32(1). The attack disrupted services in over 200 regions and saw stolen data published by the threat actor “Datacarry.”
read more →

EU fines Google €403M for mishandling location data

📌 The Irish Data Protection Commission fined Google €403 million for GDPR breaches in how three features handled location data between May 2018 and February 2020. The DPC found issues with Web & App Activity, Location History and the Location Accuracy feature, citing failures in lawful processing, transparency and accountability, and excessive data retention. Google says the case concerns historical policies and notes it has updated practices, including introducing auto-delete controls and changing defaults since 2019.
read more →

DPC fines Google €403M for location data breaches

📌 Ireland’s Data Protection Commission fined Google €403 million for GDPR breaches tied to processing users’ location data. The investigation, opened in February 2020, reviewed three features — Web & App Activity, Location History, and Location Accuracy — active during May 25, 2018 to February 4, 2020. The DPC found failures in transparency, lawful processing, and retention practices, and ordered compliance within six months. Google says it has since updated policies and added user controls for location data.
read more →

LinkedIn Pushes Limits on Secrecy in Government Subpoenas

🛡️ Microsoft’s chief legal officer argued that secrecy orders accompanying government subpoenas should be the exception, not the rule. LinkedIn, owned by Microsoft, is challenging broad government demands that bar notifying customers when their data is sought, urging courts to impose meaningful limits and oversight. The company acknowledged law enforcement needs while asserting providers and users deserve adversarial review and notice. Legislative reforms in the House aim to constrain secrecy orders and strengthen notice protections.
read more →

Radaris Loses Domains After New Jersey Privacy Case

📰 A New Jersey judge ordered radaris.com and more than a dozen related domains transferred to plaintiffs after finding the data broker repeatedly ignored removal requests under Daniel’s Law. Atlas Data Privacy Corp sued Radaris in 2024, alleging the company published personal data for state law enforcement and other officials and employed evasive shell-company tactics. The transfer follows extensive litigation, investigative reporting and documentary evidence tying multiple sites to a common operator.
read more →

Private offensive cyber program shifts risk to vendors

🔍 The White House memorandum creates a vetted program permitting private firms to conduct covert access and disruptive cyber operations under DOJ and DHS oversight, but it leaves significant legal, insurance, and commercial exposure with participating companies and their customers. The document relies on an untested reading of the CFAA for criminal protection, offers no civil safe harbor or indemnification, and may increase attribution risk internationally. Non-participating organizations can still inherit risk through shared infrastructure, vendor silence, insurance exclusions, and supply-chain telemetry.
read more →

US Sanctions Xinbi Guarantee for Global Scam Facilitation

⚖️ The US Treasury has sanctioned Xinbi Guarantee, a Chinese-language marketplace linked to large-scale fraud, money laundering and other criminal activity. The marketplace — alleged to have processed over $24bn in transactions since 2022 — connected scam operators in Southeast Asia with merchants offering financial services, fake IDs, AI deepfake tools and OTC crypto exchanges. OFAC also targeted supporting entities including SafeW Technology and Anwen Technology, while authorities and blockchain firms reported freezing $52.8m in cryptoassets and evidence the marketplace has gone offline.
read more →

France Launches New Government Cyber Response Unit

🛡️ The French national cybersecurity agency, ANSSI, has created a new incident response unit named REACTIV to support state services and coordinate responses to data breaches. The mechanism allows ANSSI to require ministries to take urgent protective measures and to lead centralized technical crisis communications during attacks affecting government services. Resource details for REACTIV have not yet been disclosed, prompting some skepticism about its operational capacity.
read more →

Class-action suits follow alleged IDScan.net mega-breach

🔍 Several class-action lawsuits have been filed against IDScan.net after reports of a potential large-scale leak of driver’s license and identity document data. The FBI is investigating following reporting that linked stolen records to a Russian forum listing called “Nexus.” Plaintiffs seek damages and improved security, while law firms are contacting potential victims and advising steps to determine exposure and preserve evidence.
read more →

French hospital fined €500k after data breach

🔒 France’s data protection authority (CNIL) fined Hôpital privé de la Loire €500,000 after a 2025 breach exposed sensitive records for 727,113 people, including 524,867 patients and 202,246 trusted third parties. The investigation found failures including lack of VPN/MFA for external users, weak access controls, and absent real-time monitoring, enabling extensive data exfiltration. The hospital informed affected patients but did not directly notify all third parties; a teen hacker claiming responsibility sold the data attempt reportedly failed.
read more →

Meta Agrees to Proposed $18B Settlement Over Teen Harms

📰 Meta has reached a proposed settlement of up to $18 billion with a bipartisan coalition of 52 state attorneys general resolving a 2023 lawsuit alleging Facebook and Instagram were designed to encourage compulsive use by children and teens. The agreement, pending court approval, requires new protections for under-18 users including default time limits, nighttime restrictions, hidden like counts, stronger parental tools, and expanded age verification. An independent auditor will oversee compliance and Meta is barred from making misleading safety claims.
read more →