Key developments
Flagstar settles 2021 breach litigation for $31.5 million
Flagstar Bank agreed to a $31.5 million class action settlement over two 2021 cyberattacks that affected about 2.19 million U.S. consumers. The January incident involved criminals infiltrating a file-sharing platform used by the bank, while the December incident involved intrusion into Flagstar's network. Claims are due August 11, 2026, and final approval is scheduled for October 1, 2026.
Why it matters
It resolves one of the larger U.S. bank breach cases and sets a concrete compensation timeline for affected consumers.
Sources & driving stories
DAPEER LAW · Valeria Linares
Dapeer Law coverageTradeify leak claim alleges 240,174 customer profiles
A threat actor posting as 'macaroni' claimed to have exfiltrated Tradeify's full customer CRM by abusing a Klaviyo private API key allegedly hardcoded in client-side JavaScript. The post advertises 240,174 unique profiles with names, emails, phone numbers, physical addresses, and limited purchase history. The claim is unverified, and Tradeify has not publicly addressed it.
Why it matters
If confirmed, the exposure would hand attackers a large phishing and fraud dataset tied to a trading platform.
Sources & driving stories
DARK WEB INFORMER
Dark Web Informer coverageEl Camino College maps response after Canvas breach
El Camino College's Academic Senate reviewed response planning on June 2 after a May 1 Canvas compromise. The Online and Distance Education Advisory Committee and Information Technology Services drafted measures including a faculty workshop on emergency remote instructional conditions. The incident was tied to ShinyHunters' breach of Canvas Free-For-Teacher accounts and leaked names, email addresses, student and faculty ID numbers, section rosters, and Canvas Inbox messages.
Why it matters
It shows a public college turning a SaaS breach into concrete operational planning.
Sources & driving stories
EL CAMINO COLLEGE THE UNION · Michelle Claire Pentreath
El Camino College The Union coverageWorth noting
WORTH NOTING
AI teddy bears expose kids' data
The warning extends privacy risk to connected toys and biometric exposure from everyday selfies.
WORTH NOTING
Singapore breach notices within 72 hours
The guide highlights strict PDPA assessment and notification timelines that multinational companies need to plan for.
Still unclear
OPEN QUESTION
Did Tradeify rotate the reported Klaviyo key?
If the key remains active, the attacker may still have access or a path to tampering.
OPEN QUESTION
Will more Canvas-linked schools disclose impact?
ECC's response suggests other institutions using the platform may need similar incident planning and notification steps.
