RC RANDOM CHAOS

1,000 Breaches In, Disclosure Delays Are Getting Longer, Not Shorter

· via Hacker News

Original source

1k Data Breaches Later, the Disclosure Lag Is Worse

Hacker News →

Troy Hunt marks Have I Been Pwned’s 1,000th breach by arguing the service is more necessary than ever, because the gap between an incident and victim notification keeps widening despite GDPR, CCPA, and similar regimes. He points to Carnival, which waited 43 days to disclose after ShinyHunters dumped 8.7 million records publicly, and Zara, which took 45 days under nearly identical circumstances. During those weeks, customers were told there was no breach while their data circulated freely on dark-web sites, clear-web mirrors, hacking forums, and Telegram channels.

The stock excuse — that organizations need to fully scope the exposed data before notifying anyone — doesn’t hold up when email addresses are trivially extractable and early warnings are cheap. Hunt’s working theory is that the real driver is the immediate wave of class-action lawsuits that follows any disclosure: companies are now optimizing for litigation posture rather than customer protection, with shareholder risk taking priority over user notification. Quoted responses from breached firms read like legal hedging, not transparency.

Compounding the lag is that disclosure may never happen at all. Privacy regulations in the UK, EU, Australia, and California all contain carve-outs that only require notification when a breach is “likely” to cause serious harm or affect rights and freedoms — a subjective threshold companies are happy to interpret generously. Firms like ZenBusiness and Charter have leaned on narrow statutory definitions of “sensitive” data to avoid contacting affected individuals entirely, leaving services like HIBP as the de facto notification channel.

Read the full article

Continue reading at Hacker News →

This is an AI-generated summary. Read the original for the full story.