Key developments
South Korea levies record Coupang privacy fine
South Korea's Personal Information Protection Commission fined Coupang 624.68 billion won ($409 million) over a breach that exposed names, contact details, delivery information and order histories for more than 33 million customers. Regulators said the company also failed to detect the incident within the 72-hour legal window and illegally collected online-activity data on about 11 million users without consent. Coupang said it regrets the incident and plans to challenge the decision.
Why it matters
It is South Korea's largest data-breach penalty and underscores enforcement against both security failures and unlawful tracking.
Sources & driving stories
REUTERS
Reuters coverageUniversity of Nottingham breach exposes 454,600 records
The University of Nottingham said a well-known cybercriminal group accessed its student record system, affecting current students and alumni. Have I Been Pwned said 454,600 former and current students may be impacted, with exposed data including names, addresses, phone numbers, IP addresses, passport numbers, ethnicity, disability information and fee-payment records. The university reported the incident to the ICO and Action Fraud and said it is working with the platform maintainer on forensic investigation.
Why it matters
It adds another large university breach to the ShinyHunters campaign and involves highly sensitive student data.
Sources & driving stories
BLEEPINGCOMPUTER · Sergiu Gatlan
BleepingComputer coverageUS Section 702 heads toward June 12 expiry
Section 702 of FISA, which allows US authorities to collect foreigners' communications abroad and search them for Americans' data without a warrant, is set to expire on June 12 after two temporary extensions this year. Congress let the authority lapse on April 20, then passed a 10-day extension and later a 45-day extension on April 30, leaving lawmakers divided over warrant rules. Privacy advocates say queries of Americans' communications may still continue under the program's existing certifications even if the statute expires.
Why it matters
The deadline could change the legal basis for one of the most consequential US surveillance authorities affecting Americans' communications.
Sources & driving stories
MALAY MAIL
Malay Mail coverageWorth noting
WORTH NOTING
ALPRs could scan Bluetooth devices
Bruce Schneier reports that Leonardo's SignalTrace would add sensors to license-plate readers so they capture phone and wearable identifiers, turning vehicle-tracking cameras into people-tracking tools.
WORTH NOTING
DentaQuest breach may reach 2.6 million
A Morgan & Morgan post says the May incident may have exposed insurance, Medicaid, ID and contact data, keeping the health-sector breach story active.
Still unclear
OPEN QUESTION
Will Congress extend Section 702 again?
The June 12 deadline is immediate, and the next vote will decide whether warrantless surveillance authority continues or enters a new legal limbo.
OPEN QUESTION
Will Coupang's challenge narrow the penalty?
The record fine is now headed into legal review, and the outcome could shape how South Korea punishes breach response failures and unlawful data collection.
