Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Sunday, June 21, 2026 · 11:48 AM EDT

Key developments

SECURITY BOULEVARD

Texas vendor breach exposes 3.1 million IDs

Security Boulevard's John Kevin Hao reported that the Texas Parks and Wildlife Department disclosed unauthorized access at an external license-system vendor used for hunting and fishing licenses and permits. Texas Cyber Command's investigation assessed potential exposure for 3,087,721 customers, including driver's license information, passport numbers, email addresses, phone numbers, and residential addresses; TPWD said Social Security numbers, dates of birth, and credit card data were not affected. Rescana reported the timeline included state cybersecurity notification on May 13, a June 12 data security incident notice, and June 18 public disclosure.

Why it matters

The breach combines large scale, government-held identity data, and third-party vendor exposure, creating elevated fraud and phishing risk for affected residents.

Sources & driving stories

SECURITY BOULEVARD · John Kevin Hao

Security Boulevard coverage
RESCANA

Nintendo employee data stolen through TinyPulse

Rescana reported that Nintendo of America confirmed internal employee survey data was stolen after a cyberattack on TinyPulse, a SaaS employee-engagement platform owned by WebMD Health Services. The report said Nintendo found no compromise of its own systems and no customer or financial data access, but threat actor Shadowbyt3$ claimed about 1GB of data including employee names, emails, survey and analytics data, bank statements, W-9 forms, employee IDs, progress plans, and reports spanning 2016 to 2026. The actor allegedly demanded $2 million and threatened to leak the data.

Why it matters

The incident underscores privacy risk from HR and employee-engagement SaaS vendors, where sensitive workforce data can be exposed even when a company’s internal systems remain uncompromised.

Sources & driving stories

MOROCCO WORLD NEWS

Morocco warns Fortinet leak exposed VPN credentials

Morocco World News's Asmae Daoudi reported that Morocco's General Directorate for Information Systems Security issued a June 18 alert about FortiBleed, a large-scale leak affecting Fortinet appliances. DGSSI said attackers targeted internet-facing FortiGate firewalls and SSL VPN gateways, allegedly exposing administrator credentials and VPN access information valid for nearly 75,000 devices worldwide, including several Moroccan organizations. The agency recommended immediate password resets, multi-factor authentication, restricted administrative access, log reviews, and FortiOS updates.

Why it matters

Credential exposure at perimeter security devices can enable follow-on intrusions and downstream data breaches across affected organizations.

Sources & driving stories

MOROCCO WORLD NEWS · Asmae Daoudi

Morocco World News coverage

Worth noting

WORTH NOTING

California ALPR class-action exposure widens

Mondaq reported that after Bartholomew v. Parking Concepts and the California Supreme Court's May 13 denial of review, plaintiffs have filed class actions against retailers, malls, hotels, parking operators, and ALPR vendors over alleged failures to post required license-plate-reader privacy policies.

WORTH NOTING

Idaho age-estimation law nears

The Lewiston Tribune reported in an opinion article that Idaho's July 1 social media law will require platforms to estimate the age of all users and obtain parental consent for users who appear 16 or younger, raising broader profiling concerns.

WORTH NOTING

Nigeria regulator presses election commission

Vanguard reported that Nigeria's Data Protection Commission has twice requested records of processing activities from the Independent National Electoral Commission amid allegations of a breach affecting electoral-database integrity.

Still unclear

OPEN QUESTION

Which vendor controls failed?

The Texas breach has no named vendor or disclosed initial-access method, while the Nintendo incident points to SaaS exposure, leaving limited visibility into how organizations should benchmark third-party privacy risk.

OPEN QUESTION

Will age checks expand user profiling?

Idaho's law targets minors but requires age estimation across all users, creating tension between child-safety regulation and minimization of behavioral tracking.