DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

2024’s Data Breaches: Breaches Handled Badly

Posted on December 27, 2024 by Dissent

There are always a ton of articles at the end of every year recapping what went wrong.  Over on TechCrunch, Zack Whittaker and Carly Page have their annual list of breaches handled poorly. This year’s list includes 23andMe, Change Healthcare, Synnovis, Snowflake, Columbus Ohio,  Salt Typhoon, Moneygram,  and HotTopic.  DataBreaches generally agrees with their recap, although the last two could be replaced by other incidents that failed to disclose transparently.  Unfortunately, there are too many of those.

On a daily basis, DataBreaches has criticized those entities that are not disclosing timely or transparently, leaving consumers and patients in the dark about what happened to their information, who’s got it now and where, and what risks they now face.

As the year draws to a close, there is still no federal regulation or law that requires all entities to notify people promptly if a breach has been discovered.  And by “discovered,” we do NOT mean after all the forensics are done and everything is tied up in a bow and run by insurers and legal counsel.  We mean that entities should let people know that their data is already being leaked on the dark web or hacking forums when they find out that it’s being leaked — even if they don’t know exactly whose data has been leaked yet.  And if identity information appears to be involved, then encourage people to put a security freeze on their credit report if they don’t have one already.

We’ll have more to say about the transparency issue when the next edition of Protenus‘s annual Breach Barometer report for U.S. medical and health data is released early in 2025.

 

 


Related:

  • Cyber-Attack On Bectu’s Parent Union Sparks UK National Security Concerns
  • John Bolton Indictment Provides Interesting Details About Hack of His AOL Account and Extortion Attempt
  • A business's cyber insurance policy included ransom coverage, but when they needed it, the insurer refused to pay. Why?
  • Scenes from a "No Kings" Protest, 10-18-25
  • No Kings. Not Today. Not Ever.
  • An arrested man's lawyer claims his client can't be ShinyHunters' leader. His argument wasn't persuasive.
Category: Commentaries and Analyses

Post navigation

← Brazilian Man Charged With Making Extortionate Threats To Publicize Stolen Data Obtained By Unlawful Computer Intrusion
Massive VW Group Data Leak Exposed 800,000 EV Owners’ Movements, From Homes To Brothels →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says
  • The Case for Making EdTech Companies Liable Under FERPA
  • NHS providers reviewing stolen Synnovis data published by cyber criminals
  • Gates Down: Third Circuit Says Breaking Employer Computer Access Policies Is Not Hacking
  • Short-term renewal of cyber information sharing law appears in bill to end shutdown
  • Yanluowang ransomware IAB pleads guilty
  • Lawsuit Alleges Ex-Intel Employee Hid 18,000 Sensitive Documents Prior to Leaving the Company
  • HIPAA, but for non-Covered Entities?
  • Manassas City Public Schools close on Monday due to cyberattack

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation
  • Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map
  • EPIC Publishes New Whitepaper Detailing Privacy Risks of Government Data Mining Programs
  • Modern cars are spying on you. Here’s what you can do about it.

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.