government healthcare social media service provider fine education finance dark web retail law enforcement web telecoms travel manufacturing phama operating system insurance legal charity app tech gaming publishing transport utilities
story hacked malware unauthorised access ransomware vulnerability accidental disclosure phishing unsecured database poor security insider threat unsecured server hacked email lost device identity theft website hacked ddos stolen documents Trojans financial inside job spear phishing RDP spyware skimming
cyber attack privacy breach notification security flaw legislation poor operations user credentials physical security customer data third party Cryptocurrency enforcement email hacked insecure storage court action encryption VPN fraud passwords zero day 3rd parties state hacking remote working stolen data cloud

Haga Hospital fined 460,000 Euros for breaching Art. 32 GDPR - Insufficient technical and organisational measures to ensure information security
Professional Football League (LaLiga) fined 250,000 Euros for breaching Art. 5 (1) a), Art. 7 (3) GDPR - Insufficient fulfilment of information obligations
U.S. Customs and Border Protection says photos of travelers were taken in a data breach
Police Officer fined 800 Euros for breaching Art. 6 GDPR - Insufficient legal basis for data processing
Nearly 12 Million Quest Diagnostics Patients’ Medical Info Exposed In New Data Breach Of Third-Party Vendor, American Medical Collection Agency
Claim management company fined 2,850 Euros for breaching Art. 5 GDPR, Art. 6 GDPR - Insufficient legal basis for data processing
Almost 100,000 Westpac customers exposed after cyber security breach
Local bank fined 2000 Euros for breaching Art. 12 (3), (4), (5) GDPR, Art. 15 GDPR, Art. 18 GDPR - Insufficient fulfilment of data subjects rights
Canva hacked - user details accessed, but passwords safe
Massachusetts Chapter 93H: SECURITY BREACHES (Mass. Gen. Laws 93H § 1)
Indiana - Data Protection Overview (Ind. Code §§ 4-1-11 et seq., 24-)
IIIinois 815 ILCS 530/  Personal Information Protection Act.
Section 28-51-104 – Idaho State Legislature (Idaho Stat. §§ 28-51-104 to 107)
HawaII Security Breach of Personal Information (Haw. Rev. Stat. § 487N)
Guam Code Title 9, Chapter 48 - Notificationof Breaches of Personal Information (2019) :: (9 GCA §§ 48.10)
Mayor fined 2000 Euros for breaching Art. 5 (1) b) GDPR, Art. 6 GDPR - Insufficient legal basis for data processing
Florida - Security of confidential personal information (Fla. Stat. § 501.171)
Understanding The First American Financial Data Leak: How Did It Happen And What Does It Mean?
First American Financial Corp. Leaked Hundreds of Millions of Title Insurance Records
Organizer of SZIGET festival and VOLT festival fined 92,146 Euros for breaching Art. 6 GDPR, Art. 5 (1) b) GDPR, Art. 13 GDPR - Insufficient legal basis for data processing
Data Breach: Truecaller Exposes Indian Users’ Data, Shows Cracks In Cyber Security Infrastructure
Directorate of Social and Child Welfare Institutions of the Ferencvaros District of Budapest fined 286 Euros for breaching Art. 33 GDPR - Insufficient fulfilment of data breach notification obligations
Hack exposed personal data of job candidates at Australia's top companies | Business Insider
Payment service provider UAB MisterTango fined 61,500 Euros for breaching Art. 5 GDPR, Art. 32 GDPR, Art. 33 GDPR - Insufficient fulfilment of data breach notification obligations
High-end Job Recruitment Site Exposes at least 13.7 million Users with Unprotected Server | Workplace Privacy, Data Management & Security Report
Police Officer fined 1,400 Euros for breaching Art. 6 GDPR - Insufficient legal basis for data processing
After account hacks, Twitch streamers take security into their own hands
Oslo Municipal Education Department fined 120,000 Euros for breaching Art. 32 GDPR - Insufficient technical and organisational measures to ensure information security
SkyMed Medical Evacuation Membership Service Exposed Data of 137k Members - Security Discovery
MongoDB breached - Over 275 Million Records Exposed by Unsecured MongoDB Database
Shopify API flaw offered access to revenue data of thousands of stores | ZDNet
Unknown fined 9,400 Euros for breaching Art. 5 (1) a) GDPR, Art. 6 GDPR - Insufficient legal basis for data processing
Italian political party Movimento 5 Stelle fined 50,000 Euros for breaching Art. 32 GDPR - Insufficient technical and organisational measures to ensure information security
Don’t Acquire a Company Until You Evaluate Its Data Security
Company in the financial sector fined 80,000 Euros for breaching Art. 5 GDPR, Art. 32 GDPR - Insufficient technical and organisational measures to ensure information security
Transnational Organized Crime Rewards Program United States Department of State
Unknown fined 1,900 Euros for breaching Art. 15 GDPR - Insufficient fulfilment of data subjects rights
Hungarian political party fined 34,375 Euros for breaching Art. 33 (1) GDPR, Art. 33 (5) GDPR, Art. 34 (1) GDPR - Insufficient fulfilment of data breach notification obligations
Unknown fined 500 Euros for breaching Unknown - Unknown
Private company working with data from publicly available sources fined 220,000 Euros for breaching Art. 14 GDPR - Insufficient fulfilment of information obligations