Materiality asks whether an investor would want to know. Whether patients are harmed is a different question.
The final count on the Conduent intrusion landed above 62 million people — third-largest in US healthcare history, at a processor most of them have never heard of.
Five million records from a platform none of the customers knew they were using. Correlated failure, uncorrelated disclosure.
The remedy is 24 months of monitoring. The scanned passport stays valid for ten years.
A containment shutdown that locked members out of retirement accounts, and a credit union suing its own provider over the standards it contracted for.
A compromise at a third-party ticketing platform used by EY’s IT staff. Ticket attachments hold whatever was needed to reproduce the problem.
Up to six million customers exposed in 2025; records published in 2026. Notification law assumes an incident that ends.
Three million licence holders through a vendor the state chose. The data does not know it was collected for a fishing permit.
A third-party software flaw reached email accounts across six Japanese providers. Choosing a different ISP bought no independence.
Ambulatory cardiac data is continuous, and continuous physiology is a behavioural record collected for a clinical reason.
Customer data through a supplier, with the airline flying normally throughout. Aviation now appears here through both operations and data.
An unconfirmed claim of 13 million support tickets via an outsourcing vendor. The access transfers; the control environment does not.
Around 32% of K-12 breaches originate at a vendor. Districts outsourced the technology and kept the accountability.
Employees of a customer of a processor. Three steps from the incident, with no point at which they could have exercised judgement.
No data taken, no notification owed, 70,000 people unable to pay a bill. Availability fails independently of confidentiality.
Another luxury house through another third-party platform. Discretion is part of what the customer is buying.
Sixty institutions down through one provider. Pooling technology is what lets small member-owned banks exist, and it concentrates the risk.
Publication is its own phase, timed for reasons unrelated to the victim. Nobody is required to tell affected people when it happens.
A commercial claimant holds the contract, can quantify the loss and can fund discovery — which is where security practice actually gets examined.
Around 30% of 2025 breaches originated with a third party. The boundary an organisation defends stopped being the boundary that determines its exposure.
Where fibre runs, which routes carry which customers, where the single points of failure sit — a dependency map for organisations that were never asked.
Vendor assessment at its most rigorous did not prevent this. The instrument measures whether a framework exists, not whether it operates.
The first case argues for stronger consent controls. The second shows they would not have helped, because nothing about the authorisation was wrong.
You can discover who your competitors bank with more readily than who runs their servers.
A client reads that their bank has had a breach. The bank’s systems were not compromised. Both are true.
The support function is where data is most accessible and least defended, because its purpose is to give people access to things.
If the corpus only records incidents above an implicit size threshold, its picture is drawn from large organisations.
A CRO holds unpublished, market-moving results for competing sponsors simultaneously, and no register would record their exposure.
Whatever the constraint was, it was not budget, headcount, expertise or tooling.
Every year the largest healthcare breach happens at a company patients have never heard of. That is where the data pools.
The bureau’s customers are lenders. The people in the database are its product.
A function nobody considers sensitive — buying things — accumulated the staff directories of nineteen client organisations.
5.4 million through a subsidiary of the group that had already produced the largest healthcare breach on record.
An RMM platform is the purest case in this database: its entire purpose is executing commands on other people’s computers.
The peer-warning argument only helps organisations that are not first. Hindsight makes May look like August.
One vendor incident becomes many provider notifications on different dates. Anyone counting breaches sees several small ones.
The finding is about the structure of the economy rather than the threat landscape — more durable and less urgent than reported.
An American software vendor’s outage changed what was on sale in British supermarkets.
Nokia was right that its systems were not breached. Its code was published anyway.
Applied for a job, was not hired, and handed over a social security number to be considered.
Customers learned their data had gone, and could not learn from whom.
A customer can change bank. An employee handed the details over as a condition of the job.
Data for sale reaches whoever pays. Data published free reaches everyone, permanently.
Each hop between merchant and issuer is a copy, and the cardholder chose none of them.
Paying bought silence about data already copied. None of the $15m was spent on the members.
A product bought to move sensitive files safely became the reason thousands of organisations lost them at once.
People write to support when something has gone wrong, and they explain it.
The alert fired in ten minutes. The device stayed on the network for 58 hours.
The same operators, the same product category, four months before MOVEit. The rehearsal nobody treated as one.
1,900 is the exposure. Three is the objective. No notification scheme has a field for that.
Something noticed on day eleven. The judgement applied to it is what failed.
The alert fired on day one. The customers heard on day sixty-one, from the attackers.