Key developments
C2N discloses email breach exposing PHI
C2N Diagnostics disclosed a breach affecting about 2,027 people after discovering unauthorized access to employees' stored email communications on March 6. The exposed material included names, dates of birth, contact information, Social Security numbers, health insurance information, and blood test analysis results. The St. Louis biotech posted notice on April 27 and is offering identity protection and credit monitoring.
Why it matters
The combination of SSNs and health information creates elevated identity-theft and medical-privacy risk.
Sources & driving stories
CLAIM DEPOT
Claim Depot coverageAkira-linked Rockville breach hits 366
Almeida Law Group said Rockville Fuel and Feed Company disclosed a breach after detecting suspicious network activity on April 1 and completing its review on May 11. The Maine Attorney General filing referenced unauthorized third-party access to files that may have contained names and other personal information for 366 individuals, with notifications sent June 5. Akira claimed responsibility on April 24 and alleged theft of passports, driver's licenses, and financial and medical data, but that claim is unconfirmed.
Why it matters
The incident may involve highly sensitive identity documents and a ransomware actor claim, raising containment and notification concerns.
Sources & driving stories
ALMEIDA LAW GROUP
Almeida Law Group coverageFlagstar agrees to $31.5M settlement
Flagstar Bank agreed to a $31.5 million class action settlement over two cyberattacks in January and December 2021 that affected about 2.19 million U.S. consumers. The settlement offers documented-loss reimbursement, residual cash, three years of three-bureau credit monitoring, and a California payment for eligible residents; claims are due August 11, 2026. Final approval is scheduled for October 1, 2026, in the Eastern District of Michigan.
Why it matters
It is one of the larger consumer privacy resolutions tied to bank breach claims and sets an upcoming claims deadline.
Sources & driving stories
DAPEER LAW · Valeria Linares
Dapeer Law coverageWorth noting
WORTH NOTING
Tradeify leak claim cites 240k profiles
A threat actor says it exfiltrated Tradeify's CRM using a hardcoded Klaviyo API key, but the claim is unverified and may indicate ongoing credential exposure if true.
WORTH NOTING
Louisiana shields hunter permit data
New bills signed by Gov. Jeff Landry will keep hunter-fisher applicant PII and certain GPS data out of public records requests starting Aug. 1.
Still unclear
OPEN QUESTION
Can Rockville verify the Akira timeline?
The ransomware group posted before the company's stated discovery date, which could indicate earlier awareness or a different compromise path.
OPEN QUESTION
Is Tradeify's Klaviyo key still active?
If the leak claim is accurate, revoking the credential is critical to stop continued access or tampering.
